IP Library Granted Patent US 11,736,522
Granted Patent B2
US 11,736,522 · App. 16/224,448 · Granted Aug 22, 2023

Server-client authentication with integrated status update

Inventors: Andrew J. Thomas (Oxfordshire, GB); Kenneth D. Ray (Seattle, WA); Karl Ackerman (Topsfield, MA)
Assignee: Sophos Limited
H04L63/1483G06F11/00G06F21/40G06F21/43G06F21/44G06F21/45G06F21/554G06F21/566G06F21/57G06F21/64H04L9/3213H04L41/0631H04L41/142H04L43/10H04L51/212H04L63/02H04L63/0209H04L63/0227H04L63/0236H04L63/0254H04L63/0428H04L63/08H04L63/0807H04L63/10H04L63/14H04L63/1408H04L63/1416H04L63/1425H04L63/1441H04L63/1466H04L63/1491H04L63/164H04L63/20H04L67/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,736,522
App. No.
16/224,448
Granted
Aug 22, 2023
Kind
B2
Abstract

An endpoint in a network periodically generates a heartbeat encoding health state information and transmits this heartbeat to other network entities. Recipients of the heartbeat may use the health state information to independently make decisions about communications with the source endpoint, for example, by isolating the endpoint to prevent further communications with other devices sharing the network with the endpoint. Isolation may be coordinated by a firewall or gateway for the network, or independently by other endpoints that receive a notification of the compromised health state.

Claims (32)

1. A computer program product for identifying compromised assets, the computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executed by an endpoint, performs the steps of:

locally monitoring a health state of the endpoint with a local security agent executing on the endpoint;

periodically creating a heartbeat encoding the health state;

transmitting the heartbeat to a network device for a local area network in an enterprise network, for communication by the network device to a threat management facility for the enterprise network; and

when the health state of the endpoint is a compromised state, encoding with the local security agent executing on the endpoint an instruction for one or more other endpoints to proactively terminate communications with the endpoint through the local area network, and broadcasting from the endpoint over the local area network the instruction for one or more other endpoints to proactively terminate communications from the endpoint to the one or more other endpoints on the local area network, wherein the local area network includes a shared medium network.

2. The computer program product of claim 1 wherein the health state is based on an indicia of potential compromise of the endpoint.

3. The computer program product of claim 1 wherein the one or more other endpoints include at least one of a second endpoint coupled to the local area network, a firewall, a router, a gateway, and a switch.

4. The computer program product of claim 1 wherein transmitting the heartbeat includes transmitting the heartbeat to a threat management facility.

5. The computer program product of claim 1 wherein locally monitoring the health state includes applying at least one of behavior analysis and static analysis to the endpoint.

6. The computer program product of claim 1 further comprising code that performs the step of cryptographically securing the heartbeat.

7. The computer program product of claim 6 wherein cryptographically securing the heartbeat includes digitally signing the heartbeat.

8. A method comprising:

locally monitoring a health state of an endpoint with a locally executing security agent on the endpoint, the endpoint coupled in a communicating relationship with a local area network;

periodically creating a heartbeat encoding the health state;

transmitting the heartbeat to a network device for the local area network in an enterprise network, for communication by the network device to a threat management facility for the enterprise network;

when the health state of the endpoint is a compromised state, encoding an instruction with the locally executing security agent executing on the endpoint for one or more other endpoints in a local area network with the endpoint to proactively terminate communications with the endpoint; and

transmitting from the endpoint over the local area network the instruction to proactively terminate communications from the endpoint to the one or more other endpoints in the local area network, wherein the local area network includes a shared medium network.

9. The method of claim 8 wherein the health state is based on an indicia of potential compromise of the endpoint.

10. The method of claim 8 wherein the network device includes at least one of a firewall, a router, a gateway, and a switch.

11. The method of claim 8 wherein transmitting the instruction includes transmitting the instruction to a router for the local area network.

12. The method of claim 8 wherein transmitting the heartbeat includes transmitting the heartbeat to the threat management facility for the enterprise network.

13. The method of claim 8 wherein the local area network includes an Ethernet local area network or a WiFi local area network.

14. The method of claim 13 wherein transmitting the instruction includes broadcasting a notification on the local area network.

15. The method of claim 8 wherein locally monitoring the health state includes applying at least one of behavior analysis and static analysis to the endpoint.

16. The method of claim 8 further comprising cryptographically securing the heartbeat.

17. The method of claim 16 wherein cryptographically securing the heartbeat includes digitally signing the heartbeat.

18. The method of claim 16 wherein cryptographically securing the heartbeat includes encrypting contents of the heartbeat.

19. The method of claim 8 wherein the local area network includes a peer-to-peer network.

20. An endpoint comprising:

a network interface configured to couple the endpoint in a communicating relationship with one or more devices through a local area network;

a memory; and

a processor configured by computer executable code stored in the memory to perform the steps of locally monitoring a health state of the endpoint with a locally executing security agent on the endpoint, periodically creating a heartbeat encoding the health state, transmitting the heartbeat to a network device for the local area network in an enterprise network, for communication by the network device to a threat management facility for the enterprise network, when the health state of the endpoint is a compromised state, encoding an instruction with the locally executing security agent for one or more other endpoints to proactively terminate communications with the endpoint, and transmitting from the endpoint over the local area network the instruction to proactively terminate communications with the endpoint to the one or more other endpoints, wherein the local area network includes a shared medium network.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2019
From: THOMAS, ANDREW J.; RAY, KENNETH D.; ACKERMAN, KARL
To: SOPHOS LIMITED
Reel/Frame 050345/0162 →