IP Library Granted Patent US 12,386,986
Granted Patent B1
US 12,386,986 · App. 18/046,065 · Granted Aug 12, 2025

Endpoint security synchronization

Inventors: Robert Clowser (Fredericksburg, VA); Dustin Weathers (Huntersville, NC)
Assignee: Wells Fargo Bank, N.A.
G06F21/62
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,386,986
App. No.
18/046,065
Granted
Aug 12, 2025
Kind
B1
Abstract

A computing system is configured to manage and synchronize indicators-of-attack (IOA) rules across multiple tenants of an Endpoint Detection and Response (EDR) tool. The computing system is configured to compare rules between an indicated source tenant and a destination tenant. The computing system may then generate output indicating common rules, updated rules, and missing rules between the source and destination tenants. A user, or the system itself, may update the rules at the destination tenant based on the rules at the source tenant. Such an endpoint security synchronization system avoids problems that may occur with manually transferring IOA rules across multiple tenants of an EDR tool which may result in errors that result in false or misleading security alerts.

Claims (57)

1. A method comprising:

receiving, at a computing system, source data including first endpoint indicators-of-attack (IOA) security rules for a source tenant of an Endpoint Detection and Response (EDR) system, wherein the EDR system serves a plurality of tenants that include the source tenant;

receiving, at the computing system, destination data including second endpoint IOA security rules for a destination tenant of the plurality of tenants served by the EDR system;

performing, at the computing system, a difference operation between the first endpoint IOA security rules of the source data and the second endpoint IOA security rules of the destination data;

generating, at the computing system, data representative of a user interface for display at an administrator computing device, the user interface indicating common rules, updated rules, and missing rules between the first endpoint IOA security rules for the source tenant and the second endpoint IOA security rules for the destination tenant; and

based on user input received via the user interface, automatically updating, at the computing system, the second endpoint IOA security rules to synchronize the first endpoint IOA security rules for the source tenant and the second endpoint IOA security rules for the destination tenant.

2. The method of claim 1 , wherein automatically updating the second endpoint IOA security rules for the destination tenant is based on the first endpoint IOA security rules for the source tenant.

3. The method of claim 1 , wherein automatically updating the second endpoint IOA security rules for the destination tenant includes replacing one or more of the second endpoint IOA security rules for the destination tenant with one or more of the first endpoint IOA security rules for the source tenant.

4. The method of claim 1 , wherein receiving the source data comprises receiving the source data from the EDR system via an EDR application programming interface (API).

5. The method of claim 1 , wherein receiving the source data comprises receiving the source data from a repository.

6. The method of claim 1 , wherein the source data and the destination data are in a JavaScript Object Notation (JSON) format.

7. The method of claim 1 , wherein generating the data representative of the user interface includes:

determining, at the computing system, different colors to assign to each of the common rules, the updated rules, and the missing rules; and

generating data representative of the different colors as part of the user interface indicating the common rules, the updated rules, and the missing rules.

8. The method of claim 1 , wherein generating the data representative of the user interface further comprises:

generating data representative of a source selection interface so as to allow a user to select a version of the source data from multiple versions of the source data to use for the difference operation with the destination data, and wherein performing the difference operation further comprises:

comparing the multiple versions of the source data to the destination data.

9. The method of claim 1 , wherein the user input is first user input, the method further comprising:

generating data representative of a source data user interface to display the source data;

receiving second user input via the user interface, wherein the second user input includes modifications to the source data; and

producing edited source data based on the second user input, and

wherein automatically updating the second endpoint IOA security rules for the destination tenant is based on the edited source data.

10. The method of claim 1 , wherein performing the difference operation comprises comparing characters of text of the first IOA security rules of the source data and the second endpoint IOA security rules of the destination data to determine which rules of the first IOA security rules of the source data and the second endpoint IOA security rules have differences.

11. A computing system comprising:

a memory; and

one or more processors in communication with the memory and configured to:

receive source data including first endpoint indicators-of-attack (IOA) security rules for a source tenant of an Endpoint Detection and Response (EDR) system, wherein the EDR system serves a plurality of tenants that include the source tenant;

receive destination data including second endpoint IOA security rules for a destination tenant of the EDR system;

perform a difference operation between the first endpoint IOA security rules of the source data and the second endpoint IOA security rules of the destination data;

generate data representative of a user interface for display at an administrator computing device, the user interface indicating common rules, updated rules, and missing rules between the first endpoint IOA security rules for the source tenant and the second endpoint IOA security rules for the destination tenant; and

based on user input received via the user interface, automatically update the second endpoint IOA security rules to synchronize the first endpoint IOA security rules for the source tenant and the second endpoint IOA security rules for the destination tenant.

12. The computing system of claim 11 , wherein to automatically update the second endpoint IOA security rules for the destination tenant, the one or more processors are further configured to:

automatically update the second endpoint IOA security rules for the destination tenant based on the first endpoint IOA security rules for the source tenant.

13. The computing system of claim 11 , wherein to automatically update the second endpoint IOA security rules for the destination tenant, the one or more processors are further configured to:

replace one or more of the second endpoint IOA security rules for the destination tenant with one or more of the first endpoint IOA security rules for the source tenant.

14. The computing system of claim 11 , wherein to receive the source data, the one or more processors are further configured to:

receive the source data from an EDR application programming interface (API).

15. The computing system of claim 11 , wherein to receive the source data, the one or more processors are further configured to:

receive the source data from a repository.

16. The computing system of claim 11 , wherein the source data and the destination data are in a JavaScript Object Notation (JSON) format.

17. The computing system of claim 11 , wherein to generate the data representative of the user interface, the one or more processors are further configured to:

determine different colors to assign to each of the common rules, the updated rules, and the missing rules; and

generate data representative of the different colors as part of the user interface indicating the common rules, the updated rules, and the missing rules.

18. The computing system of claim 11 , wherein to generate the data representative of the user interface, the one or more processors are further configured to:

generate data representative of a source selection interface so as to allow a user to select a version of the source data from multiple versions of the source data to use for the difference operation with the destination data, and wherein to perform the difference operation, the one or more processors are further configured to:

compare the multiple versions of the source data to the destination data.

19. The computing system of claim 11 , wherein the user input is first user input, and wherein the one or more processors are further configured to:

generate data representative of a source data user interface to display the source data;

receive second user input via the user interface, wherein the second user input includes modifications to the source data; and

produce edited source data based on the second user input, and

wherein to automatically update the second endpoint IOA security rules for the destination tenant is based on the edited source data.

20. A non-transitory computer readable medium comprising instructions that when executed cause one or more processors to:

receive source data including first endpoint indicators-of-attack (IOA) security rules for a source tenant of an Endpoint Detection and Response (EDR) system, wherein the EDR system serves a plurality of tenants that include the source tenant;

receive destination data including second endpoint IOA security rules for a destination tenant of the plurality of tenants served the EDR system;

perform a difference operation between the first endpoint IOA security rules of the source data and the second endpoint IOA security rules of the destination data;

generate data representative of a user interface for display at an administrator computing device, the user interface indicating common rules, updated rules, and missing rules between the first endpoint IOA security rules for the source tenant and the second endpoint IOA security rules for the destination tenant; and

based on user input received via the user interface, automatically update the second endpoint IOA security rules to synchronize the first endpoint IOA security rules for the source tenant and the second endpoint IOA security rules for the destination tenant.

Assignments (2)
REQUEST FOR ADDRESS CHANGE Recorded Dec 5, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 073895/0426 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 3, 2022
From: CLOWSER, ROBERT; WEATHERS, DUSTIN
To: WELLS FARGO BANK, N.A.
Reel/Frame 061648/0117 →
References Cited (31)
US 9282122B2 · Cabrera et al. · 2016 [cited by applicant]
US 10554493B2 · Kompella et al. · 2020 [cited by applicant]
US 10873596B1 · Bourget · 2020 [cited by examiner]
US 10944720B2 · Zivic · 2021 [cited by applicant]
US 11153180B1 · Venkata et al. · 2021 [cited by applicant]
US 11196629B2 · Tedaldi et al. · 2021 [cited by applicant]
US 11290478B2 · Weingarten et al. · 2022 [cited by applicant]
US 11522874B2 · Compton · 2022 [cited by examiner]
US 11736527B1 · Joseph Durairaj · 2023 [cited by examiner]
US 20180234457A1 · Rajkumar · 2018 [cited by examiner]
US 20200186569A1 · Milazzo · 2020 [cited by examiner]
US 20200272741A1 · Bhatia · 2020 [cited by examiner]
US 20200329058A1 · Paine · 2020 [cited by examiner]
US 20200336914A1 · Kaushik · 2020 [cited by examiner]
US 20210144178A1 · Bailey · 2021 [cited by examiner]
US 20210273970A1 · Alshech · 2021 [cited by examiner]
US 20220014535A1 · Weingarten · 2022 [cited by examiner]
US 20220021683A1 · Cassidy et al. · 2022 [cited by applicant]
US 20220086035A1 · Devaraj · 2022 [cited by examiner]
US 20220150282A1 · Bailey · 2022 [cited by examiner]
US 20220198010A1 · Ladnai · 2022 [cited by examiner]
US 20220391505A1 · Kurogome · 2022 [cited by examiner]
US 20220417259A1 · Kulaga · 2022 [cited by examiner]
US 20230113375A1 · Thomas · 2023 [cited by examiner]
US 20230247048A1 · Samosseiko · 2023 [cited by examiner]
US 20230319071A1 · Durbin · 2023 [cited by examiner]
US 20240281532A1 · Baldwin · 2024 [cited by examiner]
EP 2819346A1 · 2014 [cited by applicant]
WO 2016118478A2 · 2016 [cited by applicant]
Islam, Chadni, Muhammad Ali Babar, and Surya Nepal. “A multi-vocal review of security orchestration.” ACM Computing Surveys (CSUR) 52.2 (2019): 1-45. (Year: 2019). [cited by examiner]
V. Del Piccolo, A. Amamou, K. Haddadou and G. Pujolle, “A Survey of Network Isolation Solutions for Multi-Tenant Data Centers,” in IEEE Communications Surveys & Tutorials, vol. 18, No. 4, pp. 2787-2821, Fourthquarter 20… [cited by examiner]