IP Library Granted Patent US 11,423,156
Granted Patent B2
US 11,423,156 · App. 16/600,986 · Granted Aug 23, 2022

Detecting vulnerabilities in managed client devices

Inventors: Scott Harlow Kelley (Atlanta, GA); Adarsh Subhash Chandra Jain (Atlanta, GA); Stephen Turner (Atlanta, GA)
Assignee: AirWatch LLC
G06F21/577G06F21/56G06F2221/034H04W12/06H04W12/37
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,423,156
App. No.
16/600,986
Granted
Aug 23, 2022
Kind
B2
Abstract

The disclosure relates to detecting vulnerabilities in managed client devices. A system determines whether a vulnerability scan of a computing device is required to be performed. The system installs a vulnerability detection component in the computing device in response to determining that the vulnerability scan is required to be performed. The system requests the vulnerability detection component to perform the vulnerability scan of the computing device. The system transmits a result of the vulnerability scan to a remote management service for the computing device.

Claims (51)

1. A method of analyzing a computing device prior to enrolling the computing device with a remote management service, comprising:

initiating an enrollment of the computing device with the remote management service;

determining that the remote management service requires a vulnerability scan of the computing device to be performed prior to enrolling the computing device with the remote management service;

installing a configuration profile received from the remote management service, wherein the configuration profile specifying a restriction for the computing device and a location of an installation package of a vulnerability detection component;

installing the vulnerability detection component in the computing device, the vulnerability detection component being installed by executing the installation package obtained for the vulnerability detection component from the location specified by the configuration profile;

requesting the vulnerability detection component to perform a vulnerability scan of the computing device;

transmitting a result of the vulnerability scan to the remote management service; and

performing one or more remedial actions in response to the result of the vulnerability scan,

wherein the remedial actions include:

associating the computing device with a quarantine state within the remote management service when the result of the vulnerability scan indicates that a vulnerability is present in the computing device, wherein the quarantine state restricts the computing device to access to a subset of the services provided by the remote management service, and

receiving a replacement configuration profile with stricter restriction from the remote management service when the result of the vulnerability scan indicates that a vulnerability is present, the replacement configuration profile preventing access to enterprise resources.

2. The method of claim 1 , further comprising authenticating the vulnerability detection component using a public key assigned to a developer of the vulnerability detection component.

3. The method of claim 1 , further comprising:

performing the vulnerability scan of the computing device at a time when the computing device is associated with the quarantine state; and disassociating the computing device with the quarantine state in response to the result of the vulnerability scan indicating that the vulnerability is not present in the computing device.

4. The method of claim 1 , further comprising: obtaining a configuration profile for the computing device from the remote management service; and determining that the configuration profile specifies that the vulnerability scan of the computing device is required to be performed.

5. The method of claim 1 , further comprising:

obtaining a configuration profile for the computing device from the remote management service; and obtaining an installation package for the vulnerability detection component from a location specified by the configuration profile.

6. The method of claim 1 , wherein the vulnerability detection component comprises an application configured to detect an operating system vulnerability.

7. A system for analyzing a computing device prior to enrolling the computing device with a remote management service, comprising:

the computing device;

a storage device storing a plurality of computer instructions executable by the computing device, wherein the plurality of computer instructions cause the computing device to at least:

initiate an enrollment of the computing device with the remote management service;

determine that the remote management service requires a vulnerability scan of the computing device to be performed prior to enrolling the computing device with the remote management service;

install a configuration profile received from the remote management service, wherein the configuration profile specifying a restriction for the computing device and a location of an installation package of a vulnerability detection component;

install the vulnerability detection component in the computing device, the vulnerability detection component being installed by executing the installation package obtained for the vulnerability detection component from the location specified by the configuration profile;

request the vulnerability detection component to perform a vulnerability scan of the computing device;

transmit a result of the vulnerability scan to the remote management service; and

perform one or more remedial actions in response to the result of the vulnerability scan, wherein the remedial actions include:

associate the computing device with a quarantine state within the remote management service when the result of the vulnerability scan indicates that a vulnerability is present in the computing device, wherein the quarantine state restricts the computing device to access to a subset of the services provided by the remote management service, and

receive a replacement configuration profile with stricter restriction from the remote management service when the result of the vulnerability scan indicates that a vulnerability is present, the replacement configuration profile prevents access to enterprise resources.

8. The system of claim 6 , wherein the plurality of computer instructions

further cause the computing device to at least authenticate the vulnerability detection component using a public key assigned to a developer of the vulnerability detection component.

9. The system of claim 6 , wherein the plurality of computer instructions further cause the computing device to at least: perform the vulnerability scan of the computing device at a time when the computing device is associated with the quarantine state; and disassociate the computing device with the quarantine state in response to the result of the vulnerability scan indicating that the vulnerability is not present in the computing device.

10. The system of claim 6 , wherein the plurality of computer instructions further cause the computing device to at least: obtain a configuration profile for the computing device from the remote management service; and determine that the configuration profile specifies that the vulnerability scan of the computing device is required to be performed.

11. The system of claim 6 , wherein the plurality of computer instructions further cause the computing device to at least: obtain a configuration profile for the computing device from the remote management service; and obtaining an installation package for the vulnerability detection component from a location specified by the configuration profile.

12. The system of claim 6 , wherein the vulnerability detection component comprises at least one of an antivirus application or an application configured to detect an operating system vulnerability.

13. A non-transitory computer-readable medium for analyzing a computing device prior to enrolling the computing device with a remote management service, the non-transitory computer-readable medium storing a plurality of computer instructions executable by the computing device, wherein the plurality of computer instructions cause the computing device to at least:

initiate an enrollment of the computing device with the remote management service;

determine that the remote management service requires a vulnerability scan of the computing device to be performed prior to enrolling the computing device with the remote management service;

install a configuration profile received from the remote management service, wherein the configuration profile specifying a restriction for the computing device and a location of an installation package of a vulnerability detection component;

install the vulnerability detection component in the computing device, the vulnerability detection component being installed by executing the installation package obtained for the vulnerability detection component from the location specified by the configuration profile;

request the vulnerability detection component to perform a vulnerability scan of the computing device;

transmit a result of the vulnerability scan to the remote management service; and

perform one or more remedial actions in response to the result of the vulnerability scan, wherein the remedial actions include:

associate the computing device with a quarantine state within the remote management service when the result of the vulnerability scan indicates that a vulnerability is present in the computing device, wherein the quarantine state restricts the computing device to access to a subset of the services provided by the remote management service,

receive a replacement configuration profile with stricter restriction from the remote management service when the result of the vulnerability scan indicates that a vulnerability is present, the replacement configuration profile prevents access to enterprise resources.

14. The non-transitory computer-readable medium of claim 13 , wherein the plurality of computer instructions further cause the computing device to at least authenticate the vulnerability detection component using a public key assigned to a developer of the vulnerability detection component.

15. The non-transitory computer-readable medium of claim 13 , wherein the plurality of computer instructions further cause the computing device to at least: perform the vulnerability scan of the computing device at a time when the computing device is associated with the quarantine state; and disassociate the computing device with the quarantine state in response to the result of the vulnerability scan indicating that the vulnerability is not present in the computing device.

16. The non-transitory computer-readable medium of claim 13 , wherein the plurality of computer instructions further cause the computing device to at least: obtain a configuration profile for the computing device from the remote management service; and determine that the configuration profile specifies that the vulnerability scan of the computing device is required to be performed.

17. The non-transitory computer-readable medium of claim 13 , wherein the plurality of computer instructions further cause the computing device to at least: obtain a configuration profile for the computing device from the remote management service; and obtain an installation package for the vulnerability detection component from a location specified by the configuration profile.

18. The non-transitory computer-readable medium of claim 13 , wherein the vulnerability detection component comprises at least one of an antivirus application or an application configured to detect an operating system vulnerability.

Assignments (2)
PATENT ASSIGNMENT Recorded Aug 5, 2024
From: AIRWATCH LLC
To: OMNISSA, LLC
Reel/Frame 068327/0670 →
SECURITY INTEREST Recorded Jul 3, 2024
From: OMNISSA, LLC
To: UBS AG, STAMFORD BRANCH
Reel/Frame 068118/0004 →