IP Library Granted Patent US 10,839,073
Granted Patent B2
US 10,839,073 · App. 16/206,187 · Granted Nov 17, 2020

System and method for operating a collector at an endpoint device

Inventors: Peidong Chen (San Jose, CA); Manikandan Thiagarajan (Cupertino, CA); Michael Miller (Boulder Creek, CA); Xin Hu (Pleasanton, CA)
Assignee: Forcepoint, LLC
G06F21/554G06F21/552H04L63/20G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,839,073
App. No.
16/206,187
Granted
Nov 17, 2020
Kind
B2
Abstract

A method, system and computer-usable medium are disclosed for operating a collector at an endpoint device are disclosed. Certain embodiments include a computer-implemented method for operating an endpoint collector at an endpoint device, including: receiving, at an endpoint collector operating on the endpoint device, information corresponding to activities occurring on an endpoint platform; receiving, at the endpoint collector, one or more filter definitions; and selectively placing, by the endpoint collector, a plurality of events on a message bus, wherein a determination as to which events are placed by the endpoint collector on the message bus is based on the one or more filter definitions. Certain embodiments may include corresponding stand-alone and/or network computer systems, apparatus, and computer programs recorded on one or more computer storage devices, each configured to perform one or more of these actions.

Claims (62)

1. A computer-implemented method for operating an endpoint collector at an endpoint device, comprising:

receiving, at one or more sensors of an endpoint collector operating on the endpoint device, information corresponding to activities occurring on an endpoint platform;

receiving, by an ingress filter of the endpoint collector, one or more of collector configuration information and command and control information;

defining, by a configuration engine of the endpoint collector, one or more filter definitions using the collector configuration information;

dynamically configuring, by a collector manager of the endpoint collector, the one or more sensors using the command and control information; and

selectively placing, by an egress filter of the endpoint collector, a plurality of events on a message bus, wherein the egress filter is configured to determine which events are placed by the endpoint collector on the message bus based on the one or more filter definition.

2. The computer-implemented method of claim 1 , wherein

the one or more filter definitions are configured based on filter configuration information received at the endpoint collector over the message bus.

3. The computer-implemented method of claim 2 , wherein

the one or more filter definitions are capable of being dynamically reconfigured based on filter reconfiguration information received over the message bus during active operation of the endpoint device.

4. The computer-implemented method of claim 1 , further comprising:

selectively enabling and disabling one or more of the plurality of sensors based on the collector configuration information received by the endpoint collector over the message bus.

5. The computer-implemented method of claim 4 , wherein

the enabling and disabling of the one or more of the plurality of sensors may be dynamically reconfigured during active operation of the endpoint collector.

6. The computer-implemented method of claim 1 , wherein

the information corresponding to activities occurring on the endpoint platform include one or more of:

activities occurring in a kernel of the endpoint platform; and

activities occurring in a user space of the endpoint platform.

7. The computer-implemented method of claim 1 , further comprising:

configuring a security policy at the endpoint collector that is to be implemented at the endpoint platform; and

enforcing the security policy for the endpoint platform at the endpoint collector when an event violating the security policy is detected by the endpoint collector.

8. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

receiving, at one or more sensors of an endpoint collector operating on an endpoint device, information corresponding to activities occurring on an endpoint platform;

receiving, at an ingress filter of the endpoint collector, one or more of collector configuration information and command and control information;

defining, by a configuration engine of the endpoint collector, one or more filter definitions using the collector configuration information;

dynamically configuring, by a collector manager of the endpoint collector, the one or more sensors using the command and control information; and

selectively placing, by an egress filter of the endpoint collector, a plurality of events on a message bus, wherein the egress filter is configured to determine which events are placed by the endpoint collector on the message bus based on the one or more filter definitions.

9. The system of claim 8 , wherein

the one or more filter definitions are configured based on filter configuration information received at the endpoint collector over the message bus.

10. The system of claim 9 , wherein

the one or more filter definitions are capable of being dynamically reconfigured based on filter reconfiguration information received over the message bus during active operation of the endpoint device.

11. The system of claim 8 , wherein the instructions are further configured for:

selectively enabling and disabling one or more of the plurality of sensors based on the collector configuration information received by the endpoint collector over the message bus.

12. The system of claim 11 , wherein

the enabling and disabling of the one or more of the plurality of sensors may be dynamically reconfigured during active operation of the endpoint collector.

13. The system of claim 8 , wherein

the information corresponding to activities occurring on the endpoint platform include one or more of:

activities occurring in a kernel of the endpoint platform; and

activities occurring in a user space of the endpoint platform.

14. The system of claim 8 , wherein the instructions are further configured for:

configuring a security policy at the endpoint collector that is to be implemented at the endpoint platform; and

enforcing the security policy for the endpoint platform at the endpoint collector when an event violating the security policy is detected by the endpoint collector.

15. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

receiving, at one or more sensors of an endpoint collector operating on an endpoint device, information corresponding to activities occurring on an endpoint platform;

receiving, by an ingress filter of the endpoint collector, one or more of collector configuration information and command and control information;

defining, by a configuration engine of the endpoint collector, one or more filter definitions using the collector configuration information;

dynamically configuring, by a collector manager of the endpoint collector, the one or more sensors using the command and control information; and

selectively placing, by an egress filter of the endpoint collector, a plurality of events on a message bus, wherein the egress filter is configured to determine which events are placed by the endpoint collector on the message bus based on the one or more filter definitions.

16. The non-transitory, computer-readable storage medium of claim 15 , wherein

the one or more filter definitions are configured based on filter configuration information received at the endpoint collector over the message bus.

17. The non-transitory, computer-readable storage medium of claim 16 , wherein

the one or more filter definitions are capable of being dynamically reconfigured based on filter reconfiguration information received over the message bus during active operation of the endpoint device.

18. The non-transitory, computer-readable storage medium of claim 15 , wherein the instructions are further configured for:

selectively enabling and disabling one or more of the plurality of sensors based on the collector configuration information received by the endpoint collector over the message bus.

19. The non-transitory, computer-readable storage medium of claim 18 , wherein

the enabling and disabling of the one or more of the plurality of sensors may be dynamically reconfigured during active operation of the endpoint collector.

20. The non-transitory, computer-readable storage medium of claim 15 , wherein the instructions are further configured for:

configuring a security policy at the endpoint collector that is to be implemented at the endpoint platform; and

enforcing the security policy for the endpoint platform at the endpoint collector when an event violating the security policy is detected by the endpoint collector.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055479/0676 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 15, 2019
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 048613/0636 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2018
From: CHEN, PEIDONG; THIAGARAJAN, MANIKANDAN; MILLER, MICHAEL; HU, XIN
To: FORCEPOINT, LLC
Reel/Frame 047751/0693 →