IP Library Granted Patent US 11,599,638
Granted Patent B2
US 11,599,638 · App. 16/533,710 · Granted Mar 7, 2023

Game engine-based computer security

Inventors: Jonathan Allan Malm (Fulton, MD); Joshua Howard Stein (Palm City, FL); Patrick Nathaniel Wardle (Kula, HI)
Assignee: JAMF Software, LLC
G06F21/565A63F13/73G06F21/52G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,599,638
App. No.
16/533,710
Granted
Mar 7, 2023
Kind
B2
Abstract

A game engine sensor of a computing device executing an operating system receives first data from the operating system that represents occurrence of a monitored event. The game engine sensor sends second data corresponding to the monitored event to a game engine logic controller. A first logic block of the game engine logic controller determines, based on the second data and third data representing a system state of the computing device, that a first predicate condition is satisfied. A second logic block of the game engine logic controller determines, based on the second data and the third data, that a second predicate condition is satisfied. A computer security threat is detected based on the first and second predicate conditions being satisfied, and at least one game engine actuator is instructed to perform at least one action responsive to the computer security threat.

Claims (44)

1. A method of game engine-based computer security, the method comprising:

receiving, at a game engine sensor of a computing device executing an operating system, first data from the operating system that represents occurrence of a monitored event;

sending, from the game engine sensor, second data corresponding to the monitored event to a game engine logic controller, wherein the second data includes tag data associated with the monitored event;

determining, at a first logic block of the game engine logic controller based on the second data and third data representing a system state associated with the computing device, that a first predicate condition is satisfied;

determining, at a second logic block of the game engine logic controller based on the second data and the third data, that a second predicate condition is satisfied based at least in part on a determination that the tag data includes a first tag added to the tag data by the first logic block;

detecting a computer security threat based on the first and second predicate conditions being satisfied; and

based on detecting the computer security threat, instructing at least one game engine actuator to perform at least one action responsive to the computer security threat.

2. The method of claim 1 , wherein the game engine sensor comprises a file system monitor, a process monitor, an authentication monitor, a download monitor, a screenshot monitor, a removable media monitor, a synthetic click monitor, a volume monitor, a user activity resumption monitor, a camera monitor, a microphone monitor, or any combination thereof.

3. The method of claim 1 , wherein the second data includes a type of the monitored event, a path of the monitored event, directory information associated with the monitored event, app information associated with the monitored event, or any combination thereof.

4. The method of claim 1 , wherein the second data includes information regarding a file associated with the monitored event, whether the file is modified, information regarding content of the file, or any combination thereof.

5. The method of claim 1 , wherein the second data includes information regarding an executing process associated with the monitored event.

6. The method of claim 1 , wherein the at least one action comprises updating the system state.

7. The method of claim 1 , wherein the at least one action comprises generating an alert.

8. The method of claim 1 , wherein the at least one action comprises quarantining a file, deleting a file, gathering additional data regarding the monitored event, terminating a process, adjusting a firewall, terminating a network connection, or any combination thereof.

9. The method of claim 1 , wherein the game engine logic controller is executed by a mobile device management (MDM) server, and wherein the monitored event occurs at a first managed computing device remote from the MDM server.

10. The method of claim 9 , wherein a second monitored event occurs at a second managed computing device, and wherein the computer security threat is detected further based on the occurrence of the second monitored event.

11. The method of claim 9 , wherein the system state comprises state information associated with a plurality of managed computing devices.

12. The method of claim 1 , wherein the at least one action comprises initiating sending of a command to a plurality of managed computing devices.

13. The method of claim 1 , further comprising querying the system state based on at least a portion of the second data.

14. A system comprising:

at least one processor; and

a memory storing instructions executable by the at least one processor to:

receive, at a game engine sensor, first data from an operating system that represents occurrence of a monitored event;

send, from the game engine sensor, second data corresponding to the monitored event to a game engine logic controller, wherein the second data includes tag data associated with the monitored event;

determine, at a first logic block of the game engine logic controller based on the second data and third data representing a system state associated with a computing device, that a first predicate condition is satisfied;

determine, at a second logic block of the game engine logic controller based on the second data and the third data, that a second predicate condition is satisfied based at least in part on a determination that the tag data includes a first tag added to the tag data by the first logic block;

detect a computer security threat based on the first and second predicate conditions being satisfied; and

based on the detection of the computer security threat, instruct at least one game engine actuator to perform at least one action responsive to the computer security threat.

15. The system of claim 14 , further comprising a mobile device management (MDM) server that includes the at least one processor and the memory.

16. The system of claim 15 , wherein the monitored event occurs at a first managed computing device remote from the MDM server, and wherein the at least one action comprises initiating sending of a command to a second managed computing device that is distinct from the first managed computing device.

17. A computer-readable storage device storing instructions that, when executed, cause at least one processor to perform operations comprising:

receiving, at a game engine sensor, first data from an operating system that represents occurrence of a monitored event;

sending, from the game engine sensor, second data corresponding to the monitored event to a game engine logic controller, wherein the second data includes tag data associated with the monitored event;

determining, at a first logic block of the game engine logic controller based on the second data and third data representing a system state associated with a computing device, that a first predicate condition is satisfied;

determining, at a second logic block of the game engine logic controller based on the second data and the third data, that a second predicate condition is satisfied based at least in part on a determination that the tag data includes a first tag added to the tag data by the first logic block;

detecting a computer security threat based on the first and second predicate conditions being satisfied; and

based on the detection of the computer security threat, instructing at least one game engine actuator to perform at least one action responsive to the computer security threat.

18. A method of game engine-based computer security, the method comprising:

receiving, at a game engine sensor of a first managed computing device executing an operating system, first data from the operating system that represents occurrence of a first monitored event occurring at the first managed computing device;

sending, from the game engine sensor, second data corresponding to the first monitored event to a game engine logic controller executed by a mobile device management (MDM) server remote from the first managed computing device;

determining, at a first logic block of the game engine logic controller based on the second data and third data representing a system state associated with the first managed computing device, that a first predicate condition is satisfied;

determining, at a second logic block of the game engine logic controller based on the second data and the third data, that a second predicate condition is satisfied;

detecting a computer security threat based on the first and second predicate conditions being satisfied, and based on a second monitored event occurring at a second managed computing device; and

based on detecting the computer security threat, instructing at least one game engine actuator to perform at least one action responsive to the computer security threat.

Assignments (7)
PATENT SECURITY AGREEMENT Recorded Mar 3, 2026
From: JAMF SOFTWARE, LLC
To: BLUE OWL CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 075025/0447 →
RELEASE OF SECURITY INTEREST Recorded Jan 30, 2026
From: JPMORGAN CHASE BANK, N.A., AS AGENT
To: JAMF SOFTWARE, LLC; WANDERA, INC.
Reel/Frame 073647/0447 →
SECURITY INTEREST Recorded May 3, 2024
From: JAMF SOFTWARE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 067304/0042 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT R/F 053320/0496 Recorded May 3, 2024
From: JPMORGAN CHASE BANK, N.A.
To: JAMF SOFTWARE, LLC
Reel/Frame 067309/0366 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 23, 2021
From: MALM, JONATHAN; STEIN, JOSHUA; WARDLE, PATRICK
To: DIGITA SECURITY LLC
Reel/Frame 055687/0655 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 23, 2021
From: DIGITA SECURITY LLC
To: JAMF SOFTWARE, LLC
Reel/Frame 055688/0117 →
SECURITY INTEREST Recorded Jul 27, 2020
From: JAMF SOFTWARE, LLC
To: JPMORGAN CHASE BANK, N.A., AS AGENT
Reel/Frame 053320/0496 →
Continuity (2)
Provisional Application 62715627 · Aug 7, 2018
Related Publication 20200050763A1 · Feb 13, 2020