IP Library Granted Patent US 10,546,131
Granted Patent B2
US 10,546,131 · App. 15/089,021 · Granted Jan 28, 2020

End-point visibility

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,546,131
App. No.
15/089,021
Granted
Jan 28, 2020
Kind
B2
Abstract

A system for securing electronic devices includes a processor, a storage medium communicatively coupled to the processor, and a monitoring application comprising computer-executable instructions on the medium. The instructions are readable by the processor. The monitoring application is configured to receive an indication that a client has been affected by malware, cause the client to boot from a trusted operating system image, cause a launch of a secured security application on the client from a trusted application image, and analyze a malware status of the client through the secured security application.

Claims (47)

1. At least one non-transitory machine-readable storage medium, comprising computer-executable instructions carried on the machine-readable medium, the instructions readable by a hardware processor, the instructions, when read and executed, for causing the hardware processor to:

monitor a plurality of clients for incidences of compromise; and

upon detecting an incidence of compromise on one or more of the plurality of clients, for each client:

receive an indication that the client, that is a computer that is separate from the hardware processor and that is coupled to the hardware processor using a computer network, has been affected by malware;

cause the client to be booted from a trusted operating system image;

in response to the client being rebooted from the trusted operating system image:

cause a secured security application to be launched on the client from a trusted application image; and

cause a malware status of the client to be analyzed through the secured security application to evaluate a cause of the incidence of compromise on the client;

cross-reference the indication that the client has been affected by malware with other lowed data to determine an additional indicator of compromise; and

query the client to determine whether the client is associated with the additional indicator of compromise.

2. The medium of claim 1 , further comprising instructions for causing the client to be booted through a secured module on the client.

3. The medium of claim 1 , further comprising instructions for causing the client to be booted through a secured module on the client with a communications channel independent of operating systems of the client.

4. The medium of claim 1 , further comprising instructions for causing the client to be configured to monitor for malware to generate the indication that the client has been affected by malware.

5. The medium of claim 1 , further comprising instructions for causing the client to be booted from the trusted operating system image from a read-only region of a secured storage device communicatively coupled to the client.

6. The medium of claim 1 , further comprising instructions for causing the secured security application on the client to be queried regarding additional indicators of compromise.

7. A system for securing electronic devices, comprising:

a hardware processor;

at least one non-transitory machine-readable storage medium communicatively coupled to the hardware processor; and

a monitoring application comprising computer-executable instructions on the medium, the instructions readable by the hardware processor, the monitoring application configured to:

monitor a plurality of clients for incidences of compromise; and

upon detecting an incidence of compromise on one or more of the plurality of clients, for each client:

receive an indication that the client, that is a computer that is separate from the hardware processor and that is coupled to the hardware processor using a computer network, has been affected by malware;

cause the client to be booted from a trusted operating system image;

in response to the client being rebooted from the trusted operating system image:

cause the client to launch a secured security application from a trusted application image; and

cause malware status of the client to be analyzed through the secured security application to evaluate a cause of the incidence of compromise on the client;

cross-reference the indication that the client has been affected by malware with other lowed data to determine an additional indicator of compromise; and

query the client to determine whether the client is associated with the additional indicator of compromise.

8. The system of claim 7 , wherein the monitoring application is further configured to cause the client to be booted through a secured module on the client.

9. The system of claim 7 , wherein the monitoring application is further configured to cause the client to be booted through a secured module on the client with a communications channel independent of operating systems of the client.

10. The system of claim 7 , wherein the monitoring application is further configured to configure the client to monitor for malware to generate the indication that the client has been affected by malware.

11. The system of claim 7 , wherein the monitoring application is further configured to cause the client to be booted from the trusted operating system image from a read-only region of a secured storage device communicatively coupled to the client.

12. The system of claim 7 , wherein the monitoring application is further configured to query the secured security application on the client regarding additional indicators of compromise.

13. A method of electronic device security, comprising:

monitoring a plurality of clients for incidences of compromise; and

upon detecting an incidence of compromise on one or more of the plurality of clients, for each client:

receiving at a hardware processor an indication that the client, that is a computer that is separate from the hardware processor and that is coupled to the hardware processor using a computer network, has been affected by malware;

causing the client to boot from a trusted operating system image using the hardware processor;

in response to the client being rebooted from the trusted operating system image:

causing a launch of a secured security application on the client from a trusted application image using the hardware processor; and

analyzing a malware status of the client through the secured security application using the hardware processor to evaluate a cause of the incidence of compromise on the client;

cross-referencing the indication that the client has been affected by malware with other logged data to determine an additional indicator of compromise; and

querying the client to determine whether the client is associated with the additional indicator of compromise.

14. The method of claim 13 , further comprising causing the client to boot through a secured module on the client.

15. The method of claim 13 , further comprising causing the client to boot through a secured module on the client with a communications channel independent of operating systems of the client.

16. The method of claim 13 , further comprising configuring the client to monitor for malware to generate the indication that the client has been affected by malware.

17. The method of claim 13 , further comprising causing the client to boot from the trusted operating system image from a read-only region of a secured storage device communicatively coupled to the client.

Assignments (16)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 1, 2022
From: SKYHIGH SECURITY LLC
To: MUSARUBRA US LLC
Reel/Frame 060424/0880 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2022
From: MUSARUBRA US LLC
To: SKYHIGH SECURITY LLC
Reel/Frame 060325/0105 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060248/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →