IP Library Granted Patent US 10,015,187
Granted Patent B2
US 10,015,187 · App. 15/250,300 · Granted Jul 3, 2018

System and method for performing remote security assessment of firewalled computer

Inventors: Wissam Ali-Ahmad (Cupertino, CA); Wolfgang Kandek (San Jose, CA); Holger Kruse (Redwood Shores, CA); Vikas Dewan (Redwood Shores, CA); Khair-ed-dine Mazboudi (San Jose, CA); Ganesh Jampani (Gilroy, CA); Kenneth K. Okumura (Sunnyvale, CA)
Assignee: Qualys, Inc.
H04L63/1433H04L63/0281H04L63/1408H04L63/166H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,015,187
App. No.
15/250,300
Granted
Jul 3, 2018
Kind
B2
Abstract

Methods and systems for scanning an endpoint terminal across an open computer network are disclosed. An exemplary method includes providing a scanner engine in a computer server in communication with an open computer network, and establishing a secure connection across the open computer network between the scanner engine and a scanner agent installed on the endpoint terminal in communication with the open computer network. Commands for collecting data regarding the endpoint terminal are sent from the scanner engine across the secure connection to the scanner agent. The scanner engine then receives the collected data from the scanner agent across the secure connection, analyzes the data to assess a current posture of the endpoint terminal, and determines any updates for the endpoint terminal from the analysis. Updates are sent across the secure connection to the scanner agent for installation on the endpoint terminal, and the secure connection may then be terminated.

Claims (50)

1. A method comprising:

providing an endpoint device comprising a web browser in communication with a network;

providing a scanner server in communication with the network, wherein the scanner server comprises a scanner engine;

establishing a secure layer connection between the scanner engine of the scanner server and a web browser plug-in of the endpoint device;

transmitting commands for collecting data associated with the endpoint device from the scanner engine to the web browser plug-in via the secure layer connection;

receiving data associated with the endpoint device at the scanner engine and from the web browser plug-in via the secure layer connection, wherein the received data was collected using the web browser plug-in;

analyzing the received data using the scanner engine to assess a current security vulnerability posture of the endpoint device;

identifying, using the scanner engine, an update for the endpoint device based on analyzing the received data; and

transmitting the update from the scanner engine to the endpoint device,

wherein the scanner server is coupled to the network through a proxy server,

wherein the proxy server takes over the secure layer connection in response to the web browser plug-in of the endpoint device no longer being in communication with the scanner engine of the scanner server.

2. The method of claim 1 , wherein the endpoint device is protected from the network with a firewall.

3. The method of claim 1 , wherein the web browser further comprises a graphical user interface for use by a user of the endpoint device in initiating the collection of the received data.

4. The method of claim 1 , wherein the secure layer connection encrypts at least one of the commands for collecting data associated with the endpoint device, the received data associated with the endpoint device, and the update for the endpoint device.

5. The method of claim 1 , wherein the update comprises virus definition update.

6. The method of claim 1 , wherein the secure layer connection is established without requiring credentialed access.

7. The method of claim 1 , wherein the secure layer connection is switched back from the proxy server to the web browser plug-in of the endpoint device.

8. A scanning server comprising:

at least one computer readable storage including instructions; and

at least one processing device configured to execute the instructions, wherein executing the instructions causes the at least one processing device to perform the operations of:

establishing a secure layer connection between a scanner engine comprised in the scanner server and a web browser plug-in of an endpoint device, wherein each of the scanning server and the endpoint device are in communication with a network;

transmitting commands for collecting data associated with the endpoint device from the scanner engine to the web browser plug-in via the secure layer connection;

receiving data associated with the endpoint device at the scanner engine and from the web browser plug-in via the secure layer connection, wherein the received data was collected using the web browser plug-in;

analyzing the received data using the scanner engine to assess a current security vulnerability posture of the endpoint device;

identifying, using the scanner engine, an update for the endpoint device based on analyzing the received data; and

transmitting the update from the scanner engine to the endpoint device,

wherein the scanner server is coupled to the network through a proxy server,

wherein the proxy server takes over the secure layer connection in response to the web browser plug-in of the endpoint device no longer being in communication with the scanner engine of the scanner server.

9. The scanning server of claim 8 , wherein the endpoint device is protected from the network with a firewall.

10. The scanning server of claim 8 , wherein the endpoint device comprises a web browser, and wherein the web browser comprises a graphical user interface for use by a user of the endpoint device in initiating the collection of the received data.

11. The scanning server of claim 8 , wherein the secure layer connection encrypts at least one of the commands for collecting data associated with the endpoint device, the received data associated with the endpoint device, and the update for the endpoint device.

12. The scanning server of claim 8 , wherein the update comprises virus definition updates.

13. The method of claim 8 , wherein the secure layer connection is established without requiring credentialed access.

14. The scanning server of claim 8 , wherein the secure layer connection is switched back from the proxy server to the web browser plug-in of the endpoint device.

15. A system comprising:

an endpoint device comprising a web browser in communication with a network;

a scanner server in communication with the network, wherein the scanner server comprises a scanning engine for conducting scans of the endpoint device, wherein conducting scans of the endpoint device comprises:

establishing a secure layer connection between the scanner engine of the scanner server and a web browser plug-in of the endpoint device;

transmitting commands for collecting data associated with the endpoint device from the scanner engine to the web browser plug-in via the secure layer connection;

receiving data associated with the endpoint device at the scanner engine and from the web browser plug-in via the secure layer connection, wherein the received data was collected using the web browser plug-in;

analyzing the received data using the scanner engine to assess a current security vulnerability posture of the endpoint device;

identifying, using the scanner engine, an update for the endpoint device based on analyzing the received data; and

transmitting the update from the scanner engine to the endpoint device,

wherein the scanner server is coupled to the network through a proxy server,

wherein the proxy server takes over the secure layer connection in response to the web browser plug-in of the endpoint device no longer being in communication with the scanner engine of the scanner server.

16. The system of claim 15 , wherein the endpoint device is protected from the network with a firewall.

17. The system of claim 15 , wherein the web browser further comprises a graphical user interface for use by a user of the endpoint device in initiating the collection of the received data.

18. The system of claim 15 , wherein the secure layer connection encrypts at least one of the commands for collecting data associated with the endpoint device, the received data associated with the endpoint device, and the update for the endpoint device.

19. The system of claim 15 , wherein the update comprises virus definition updates.

20. The system of claim 15 , wherein the secure layer connection is switched back from the proxy server to the web browser plug-in of the endpoint device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2016
From: ALI-AHMAD, WISSAM; KANDEK, WOLFGANG; KRUSE, HOLGER; DEWAN, VIKAS; MAZBOUDI, KHAIR-ED-DINE; JAMPANI, GANESH; OKUMURA, KENNETH K.
To: QUALYS, INC.
Reel/Frame 039584/0748 →
Continuity (5)
Continuation 14584876 · Dec 29, 2014
Continuation 13482531 · May 29, 2012
Continuation 12541869 · Aug 14, 2009
Provisional Application 61089381 · Aug 15, 2008
Related Publication 20170180409A1 · Jun 22, 2017
Cited By (2)
US 12,200,116 US 12,219,058