IP Library Granted Patent US 11,429,625
Granted Patent B2
US 11,429,625 · App. 16/813,547 · Granted Aug 30, 2022

Query engine for remote endpoint information retrieval

Inventors: Leandro Ignacio Costantino (Cabalango, AR); Cristian A. Sanchez (Cordoba, AR); Juan M. Olle (Cordoba, AR); Diego Naza Pamio (Cordoba, AR)
Assignee: Musarubra US LLC
G06F16/2471G06F16/245
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,429,625
App. No.
16/813,547
Granted
Aug 30, 2022
Kind
B2
Abstract

Embodiments are disclosed herein for remote retrieval of information from endpoints and comprise receiving a master query at an endpoint in a network environment and executing a set of one or more subqueries defined in the master query. Embodiments also comprise an execution of a first subquery that includes executing a function to produce a first output, applying one or more conditions to the first output to determine a second output, and determining a result of the master query based, at least in part, on the second output. In specific embodiments, the master query is received from another node over a network connection. In more specific embodiments, the function is executed on the endpoint to collect real-time information based on one or more parameters. In further embodiments, the function is one of a plug-in or a script.

Claims (48)

1. At least one machine readable storage medium comprising instructions that, when executed by a processor, cause the processor to:

receive a master query, by a query engine in an endpoint in a network, from a query service in another node via a network connection;

parse, by the query engine in the endpoint, the master query into code to be executed;

determine a type of action requested in the master query;

generate, by the query engine in the endpoint, a query chain to executed, wherein the query chain includes one or more subqueries;

execute, by the query engine in the endpoint, the query chain;

generate, by the query engine in the endpoint, a master query result based on the executed query chain;

cause, responsive to the master query result indicating a condition is met, a script to be executed by the endpoint to perform an action on the endpoint; and

communicate, by the query engine in the endpoint, the master query results to the query service.

2. The at least one machine readable storage medium according to claim 1 , wherein the query chain is a plurality of query chains, and wherein the plurality of query chains are executed sequentially.

3. The at least one machine readable storage medium according to claim 1 , wherein the query chain is a plurality of query chains, and wherein the plurality of query chains are executed in parallel.

4. The at least one machine readable storage medium according to claim 1 , wherein the query chain is a plurality of query chains, and wherein the master query result is generated when each of the plurality of the query chains has returned a query chain result.

5. The at least one machine readable storage medium according to claim 1 , wherein the query chain uses short circuit logic.

6. The at least one machine readable storage medium according to claim 5 , wherein the query chain is a plurality of query chains, and wherein the master query result is generated when a successful query chain result is returned.

7. The at least one machine readable storage medium according to claim 1 , wherein the action performed on the endpoint includes deleting a file, quarantining a file, sending an email, sending a notification, killing a process, rebooting the endpoint, or shutting down the endpoint.

8. An apparatus, the apparatus being an endpoint in a network and comprising:

a processor; and

a memory storing executable instructions that when executed by the processor cause the processor to:

receive, by a query engine in an endpoint, a master query from a query service in another node via a network connection;

parse, by the query engine in the endpoint, the master query into code to be executed;

determine, by the query engine in the endpoint, a type of action requested in the master query;

generate, by the query engine in the endpoint, one or more query chains to be executed, wherein the one or more query chains include one or more subqueries;

execute, by the query engine in the endpoint, the one or more query chains;

generate, by the query engine in the endpoint, a master query result based on the executed one or more query chains;

cause, responsive to the master query result indicating a condition is met, a script to be executed by the endpoint to perform an action on the endpoint; and

communicate, by the query engine in the endpoint, the master query result to the query service.

9. The apparatus of claim 8 , wherein the one or more query chains are executed sequentially.

10. The apparatus of claim 8 , wherein the one or more query chains are executed in parallel.

11. The apparatus of claim 8 , wherein the master query result is generated when each of the one or more query chains has returned a query chain result.

12. The apparatus of claim 8 , wherein the one or more query chains use short circuit logic.

13. The apparatus of claim 12 , wherein the master query result is generated when a successful query chain result is returned by the one or more query chains.

14. The apparatus of claim 8 ,

wherein the action performed on the endpoint includes deleting a file, quarantining a file, sending an email, sending a notification, killing a process, rebooting the endpoint, or shutting down the endpoint.

15. A method, comprising:

receiving a master query, by a query engine in an endpoint in a network, from a query service in another node via a network connection;

parsing, by the query engine in the endpoint, the master query into code to be executed;

determining, by the query engine in the endpoint, a type of action requested in the master query;

generating, by the query engine in the endpoint, one or more query chains to be executed, wherein the one or more query chains include one or more subqueries;

executing, by query engine in the endpoint, the one or more query chains;

generating, by the query engine in the endpoint, a master query result based on the executed one or more query chains;

causing, responsive to the master query result indicating a condition is met, a script to to be executed by the endpoint to perform an action on the endpoint; and

communicating, by the query engine in the endpoint, the master query result to the query service.

16. The method of claim 15 , wherein the one or more query chains are executed sequentially.

17. The method of claim 15 , wherein the one or more query chains are executed in parallel.

18. The method of claim 15 , wherein the master query result is generated when each of the one or more query chains has returned a query chain result.

19. The method of claim 15 , wherein the one or more query chains use short circuit logic, and wherein the master query result is generated when a successful query chain result is returned by the one or more query chains.

20. The method of claim 15 ,

wherein the action performed on the endpoint includes deleting a file, quarantining a file, sending an email, sending a notification, killing a process, rebooting the endpoint, or shutting down the endpoint.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 059284/0380 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
Continuity (2)
Continuation 14751560 · Jun 26, 2015
Related Publication 20200210424A1 · Jul 2, 2020