IP Library Granted Patent US 11,481,396
Granted Patent B2
US 11,481,396 · App. 16/851,979 · Granted Oct 25, 2022

Executing untrusted commands from a distributed execution model

Inventors: Arindam Bhattacharjee (Fremont, CA); Sourav Pal (Foster City, CA); Alexander Douglas James (Seattle, WA)
Assignee: Splunk Inc.
G06F16/24553G06F16/13G06F16/2379G06F16/2433G06F16/901G06F16/90335H04L63/10H04W12/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,481,396
App. No.
16/851,979
Granted
Oct 25, 2022
Kind
B2
Abstract

Systems and methods are disclosed for generating a distributed execution model with untrusted commands. The system can receive a query, and process the query to identify the untrusted commands. The system can use data associated with the untrusted command to identify one or more files associated with the untrusted command. Based on the files, the system can generate a data structure and include one or more identifiers associated with the data structure in the distributed execution model. The system can distribute the distributed execution model to one or more nodes in a distributed computing environment for execution.

Claims (50)

1. A computer-implemented method, comprising:

receiving a plurality of commands of a distributed execution model to execute at least a portion of a query;

identifying an untrusted command from the plurality of commands of the distributed execution model;

generating a data structure in a restricted computing environment based on a file containing computer-executable instructions associated with the untrusted command; and

executing one or more computer executable instructions based on the data structure.

2. The method of claim 1 , wherein the method is performed by a worker node in a distributed computing environment.

3. The method of claim 1 , wherein the distributed execution model comprises a directed acyclic graph.

4. The method of claim 1 , the distributed execution model includes a plurality of computer executable instructions to execute the query using a plurality of worker nodes.

5. The method of claim 1 , wherein the plurality of commands include a trusted command that is associated with libraries and dependencies that are known by a system executing the query.

6. The method of claim 1 , wherein the untrusted command is associated with libraries and dependencies that are not known by a system executing the query.

7. The method of claim 1 , wherein the untrusted command includes an identifier that corresponds to an executable portion of the data structure.

8. The method of claim 1 , wherein each of the plurality of commands is associated with one or more computation operations.

9. The method of claim 1 , further comprising instantiating the restricted computing environment to generate the data structure.

10. The method of claim 1 , further comprising communicating data associated with the untrusted command to the restricted computing environment to generate the data structure.

11. The method of claim 1 , further comprising communicating data associated with the untrusted command to the restricted computing environment to generate the data structure, wherein the data associated with the untrusted command includes an identifier of the file.

12. The method of claim 1 , further comprising communicating data associated with the untrusted command to the restricted computing environment to generate the data structure, wherein the data associated with the untrusted command includes a filename and a file location associated with the file.

13. The method of claim 1 , further comprising communicating data associated with the untrusted command to the restricted computing environment, wherein the data associated with the untrusted command includes a filename and a file location associated with the file, wherein the restricted computing environment uses the filename and file location to identify the file, and uses the file to generate the data structure.

14. The method of claim 1 , wherein generating the data structure based on the file comprises generating the data structure based on a plurality of files.

15. The method of claim 1 , wherein generating the data structure based on the file comprises generating the data structure based on a plurality of files, wherein the plurality of files include a binary file and at least one of a library, a dependent library, or a dynamic-linked list.

16. The method of claim 1 , wherein the file is a binary file.

17. The method of claim 1 , wherein the file includes a command to generate the data structure.

18. The method of claim 1 , wherein the file includes a command to generate the data structure, wherein the command included in the file indicates one or more additional files to generate the data structure.

19. The method of claim 1 , wherein the file includes a command to generate the data structure, wherein the command included in the file indicates how to generate the data structure.

20. The method of claim 1 , wherein the data structure is a computer object.

21. The method of claim 1 , further comprising:

communicating data associated with the untrusted command to the restricted computing environment, wherein the restricted computing environment generates the data structure; and

receiving the data structure from the restricted computing environment.

22. The method of claim 1 , further comprising transforming the data structure.

23. The method of claim 1 , wherein the file is located in a temporary directory of a worker node.

24. The method of claim 1 , executing one or more computer-executable instructions based on the data structure comprises executing a portion of the data structure.

25. A computing system, comprising:

one or more processing devices configured to:

receive a plurality of commands of a distributed execution model to execute at least a portion of a query;

identify an untrusted command from the plurality of commands of the distributed execution model;

generate a data structure in a restricted computing environment based on a file containing computer-executable instructions associated with the untrusted command; and

execute one or more computer executable instructions based on the data structure.

26. The system of claim 25 , wherein the one or more processing devices are further configured to:

initiate the restricted computing environment;

communicate data associated with the untrusted command to the restricted computing environment, wherein the restricted computing environment generates the data structure; and

receive the data structure from the restricted computing environment.

27. The system of claim 25 , wherein generating the data structure based on the file comprises generating the data structure based on a plurality of files, wherein the plurality of files include a binary file including a command to execute the data structure, and at least one of a library, a dependent library, a configuration file, or a dynamic-linked list.

28. Non-transitory computer readable media comprising computer-executable instructions that, when executed by a computing system, cause the computing system to:

receive a plurality of commands of a distributed execution model to execute at least a portion of a query;

identify an untrusted command from the plurality of commands of the distributed execution model;

generate a data structure in a restricted computing environment based on a file containing computer-executable instructions associated with the untrusted command; and

execute one or more computer executable instructions based on the data structure.

29. The non-transitory computer readable media of claim 28 , wherein the computer-executable instructions further cause the computing system to:

initiate the restricted computing environment;

communicate a file name and location of the file to the restricted computing environment, wherein the restricted computing environment accesses the file using the file name and location, and generates the data structure using the file; and

receive the data structure from the restricted computing environment.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 6, 2022
From: BHATTACHARJEE, ARINDAM; PAL, SOURAV; JAMES, ALEXANDER DOUGLAS
To: SPLUNK INC.
Reel/Frame 060413/0165 →
Continuity (2)
Continuation 15714424 · Sep 25, 2017
Related Publication 20200257691A1 · Aug 13, 2020
Cited By (1)
US 12,265,540