IP Library Granted Patent US 11,372,662
Granted Patent B2
US 11,372,662 · App. 17/342,669 · Granted Jun 28, 2022

Agent-based throttling of command executions

Inventor: Shreyas Khare (Toronto, CA)
Assignee: Rapid7, Inc.
G06F9/45512G06F9/3009G06F9/3836H04L47/762H04L63/1475H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,372,662
App. No.
17/342,669
Granted
Jun 28, 2022
Kind
B2
Abstract

Disclosed herein are methods, systems, and processes to perform granular and selective agent-based throttling of command executions. A resource consumption threshold is allocated to an agent process that is configured to perform data collection tasks on a host computing device. A desired throttle is generated for the agent process based on the resource consumption threshold allocated to the agent process and execution of the agent process is controlled in polling intervals. For each polling interval, a current throttle level for the agent process is determined based on a run count and a skip count of the agent process, the agent process is suspended if the agent process is active and the current throttle is greater than the desired throttle level, and the agent process is resumed if the agent process is idle and the current throttle level is not greater than the desired throttle level.

Claims (76)

1. A method comprising:

allocating a resource consumption threshold to an agent process, wherein

the agent process is configured to perform one or more data collection tasks on a host computing device;

generating a desired throttle level for the agent process based on the resource consumption threshold allocated to the agent process; and

controlling execution of the agent process in a plurality of polling intervals, comprising in each polling interval:

determining a current throttle level for the agent process based on a run count and a skip count of the agent process,

suspending the agent process if the agent process is active and the current throttle level is greater than the desired throttle level, and

resuming the agent process if the agent process is idle and the current throttle level is not greater than the desired throttle level.

2. The method of claim 1 , wherein

the run count indicates a number of polling intervals that the agent process has been active,

the skip count indicates a number of polling intervals that the agent process has been idle, and

the current throttle level is determined based on a ratio of (a) the run count and (b) a sum of the run count and the skip count.

3. The method of claim 1 , wherein

the desired throttle level indicates an efficiency value at which the agent process is to run.

4. The method of claim 1 , wherein

the controlling of the execution of the agent process is initiated in response to a determination that a resource consumption of the host computing device has exceeded a threshold.

5. The method of claim 1 , wherein

the desired throttle level is determined based on a configuration of the host computing device.

6. The method of claim 1 , wherein

the desired throttle level is determined based on one or more types of commands to be executed by the agent process.

7. The method of claim 6 , wherein

the one or more types of commands comprise one or more of:

a command search for one or more files in a file system,

a command to read a file on the file system,

a running a task automation command,

a configuration management command,

a command to extract user group policy information,

a command to search plain-text data sets,

a command to calculate a hash function checksum, and

a command to execute a script.

8. The method of claim 1 , wherein

the controlling is performed by a command execution throttling engine on the host computing device, and

the command execution throttling engine is configured to control execution of a plurality of agent processes on the host computing device.

9. The method of claim 1 , wherein

suspending the agent process comprises suspending one or more children processes of the agent process, and

resuming the agent process comprises resuming the one or more children processes of the agent process.

10. The method of claim 1 , wherein

a frequency of the polling intervals is controlled by a polling interval manager on the host computing device, and

the polling interval manager is configured to modify the frequency of the polling intervals based on one or more characteristics agent process or the host computing device.

11. A system comprising:

one or more computing systems that implement a command execution throttling engine, configured to:

allocate a resource consumption threshold to an agent process, wherein the agent process is configured to perform one or more data collection tasks on a host computing device;

generate a desired throttle level for the agent process based on the resource consumption threshold allocated to the agent process; and

control execution of the agent process in a plurality of polling intervals to, in each polling interval:

determine a current throttle level for the agent process based on a run count and a skip count of the agent process,

suspend the agent process if the agent process is active and the current throttle level is greater than the desired throttle level, and

resume the agent process if the agent process is idle and the current throttle level is not greater than the desired throttle level.

12. The system of claim 11 , wherein

the run count indicates a number of polling intervals that the agent process has been active,

the skip count indicates a number of polling intervals that the agent process has been idle, and

the current throttle level is determined based on a ratio of (a) the run count and (b) a sum of the run count and the skip count.

13. The system of claim 11 , wherein

the controlling of the execution of the agent process is initiated in response to a determination that a resource consumption of the host computing device has exceeded a threshold.

14. The system of claim 11 , wherein

the desired throttle level is determined based on a configuration of the host computing device.

15. The system of claim 11 , wherein

the desired throttle level is determined based on one or more types of commands to be executed by the agent process.

16. The system of claim 11 , wherein

to suspend the agent process, the command execution throttling engine is configured to suspend one or more children processes of the agent process, and

to resume the agent process, the command execution throttling engine is configured to resume the one or more children processes of the agent process.

17. The system of claim 11 , wherein

the command execution throttling engine implements a polling interval manager, and

the polling interval manager is configured to modify a frequency of the polling intervals based on one or more characteristics agent process or the host computing device.

18. One or more non-transitory computer-readable media storing instructions that when executed on one or more processors implement a command execution throttling engine and cause the command execution throttling engine to:

allocate a resource consumption threshold to an agent process, wherein the agent process is configured to perform one or more data collection tasks on a host computing device;

generate a desired throttle level for the agent process based on the resource consumption threshold allocated the agent process; and

control execution of the agent process in a plurality of polling intervals to, in each polling interval:

determine a current throttle level for the agent process based on a run count and a skip count of the agent process,

suspend the agent process if the agent process is active and the current throttle level is greater than the desired throttle level, and

resume the agent process if the agent process is idle and the current throttle level not greater than the desired throttle level.

19. The one or more non-transitory computer-readable media of claim 18 , wherein

the run count indicates a number of polling intervals that the agent process has been active,

the skip count indicates a number of polling intervals that the agent process has been idle, and

the instructions when executed on the one or more processors cause the command execution throttling engine to determine the current throttle level based on a ratio of (a) the run count and (b) a sum of the run count and the skip count.

20. The one or more non-transitory computer-readable media of claim 18 , wherein

the instructions when executed on the one or more processors cause the command execution throttling engine to determine the desired throttle level based on one or more types of commands to be executed by the agent process.

Assignments (3)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2024
From: KHARE, SHREYAS
To: RAPID7, INC.
Reel/Frame 068702/0534 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2022
From: KHARE, SHREYAS
To: RAPID7, INC.
Reel/Frame 058926/0778 →
Continuity (2)
Continuation 16881103 · May 22, 2020
Related Publication 20210365283A1 · Nov 25, 2021