Endpoint agent management systems and methods for remote endpoint security
Abstract
An endpoint security system having a Secured Authentication For Enterprise (SAFE) server is enhanced with an auxiliary service. The auxiliary service receives a request to run a job on an endpoint of an enterprise computer network, queues up the job in a central job store, and monitors whether an agent on the endpoint has checked in with the SAFE server. Responsive to the agent on the endpoint checking in with the SAFE server, the auxiliary service establishes, through a secure connection with the SAFE server, a connection with the agent on the endpoint and determines whether the agent has any jobs queued up in the central job store. If so, the auxiliary service dispatches the job from the central job store to the agent on the endpoint through the secure connection with the SAFE server and starts the job by the agent on the endpoint.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method of secure job execution on an endpoint, comprising:
receiving, at a job server, a request to execute a job on an endpoint, the endpoint executing an agent, the agent to execute the job and track a job status of the job, the job status indicating one of: the job has not started executing on the endpoint, or the job has completed executing on the endpoint, the job associated with job data on the endpoint; queuing the job request on a job store coupled to the job server; determining, by the job server, that the agent has checked-in; determining, by the job server, that the job queued on the job store is associated with the agent that checked-in; querying the agent on the endpoint to determine the job status of the queued job; if the job status indicates that the job has not started execution on the endpoint, sending a request to the agent on the endpoint to start the job; and if the job status indicates that the job has completed execution on the endpoint, sending a request to receive the associated job data from the agent on the endpoint.
2 . The method according to claim 1 , wherein the request to execute the job is received from a secure server coupled to the job server, wherein the secure server is coupled to the endpoint via a network, wherein the job server determines that the agent has checked-in by receiving a checked-in agent status message from the secure server, and wherein the job server queries the agent regarding the job status via the secure server.
3 . The method according of claim 2 , wherein the job comprises a plurality of jobs, wherein the endpoint comprises a plurality of endpoints, wherein the agent comprises a plurality of agents, each agent executing on one of the plurality of endpoints and each job executing on one of the plurality of endpoints, and wherein the job status of the job executing on one of the plurality of endpoints is received from the agent executing on the one of the plurality of endpoints that has checked-in with the secure server.
4 . The method according to claim 2 , wherein the job comprises a plurality of jobs executing on the endpoint, wherein the job status for each of the plurality of jobs is received by the job server via the secure server, and wherein the job server sends the request to start the job for each job that has not started execution on the endpoint and sends the request to receive the associated job data for each job that has completed execution on the endpoint.
5 . The method of claim 2 , wherein the job server is indirectly coupled to the endpoint, the method further comprising:
authenticating, by the secure server, the endpoint.
6 . The method of claim 2 , wherein the agent has an offline status when not executing on the endpoint, or has an online status when executing on the endpoint, the agent checking-in with the secure server when changing from the offline status to the online status.
7 . The method of claim 6 , wherein the agent is configured to check-in based on one or more check-in parameters.
8 . A system of secure job execution on an endpoint, comprising:
a processor; a non-transitory computer-readable medium; and instructions stored on the non-transitory computer-readable medium and translatable by the processor for providing a job server configured for:
receiving a request to execute a job on an endpoint, the endpoint executing an agent, the agent to execute the job and track a job status of the job, the job status indicating one of: the job has not started executing on the endpoint, or the job has completed executing on the endpoint, the job associated with job data on the endpoint;
queuing the job request on a job store coupled to the job server;
determining that the agent has checked-in;
determining that the job queued on the job store is associated with the agent that checked-in;
querying the agent on the endpoint to determine the job status of the queued job;
if the job status indicates that the job has not started execution on the endpoint, sending a request to the agent on the endpoint to start the job; and
if the job status indicates that the job has completed execution on the endpoint, sending a request to receive the associated job data from the agent on the endpoint.
9 . The system according to claim 8 , wherein the request to execute the job is received from a secure server coupled to the job server, wherein the secure server is coupled to the endpoint via a network, wherein the job server determines that the agent has checked-in by receiving a checked-in agent status message from the secure server, and wherein the job server queries the agent regarding the job status via the secure server.
10 . The system according of claim 9 , wherein the job comprises a plurality of jobs, wherein the endpoint comprises a plurality of endpoints, wherein the agent comprises a plurality of agents, each agent executing on one of the plurality of endpoints and each job executing on one of the plurality of endpoints, and wherein the job status of the job executing on one of the plurality of endpoints is received from the agent executing on the one of the plurality of endpoints that has checked-in with the secure server.
11 . The system according to claim 9 , wherein the job comprises a plurality of jobs executing on the endpoint, wherein the job status for each of the plurality of jobs is received by the job server via the secure server, and wherein the job server sends the request to start the job for each job that has not started execution on the endpoint and sends the request to receive the associated job data for each job that has completed execution on the endpoint.
12 . The system of claim 9 , wherein the job server is indirectly coupled to the endpoint and wherein the instructions are further translatable by the processor for:
authenticating, by the secure server, the endpoint.
13 . The system of claim 9 , wherein the agent has an offline status when not executing on the endpoint, or has an online status when executing on the endpoint, the agent checking-in with the secure server when changing from the offline status to the online status.
14 . The system of claim 13 , wherein the agent is configured to check-in based on one or more check-in parameters.
15 . A computer program product comprising a non-transitory computer-readable medium storing instructions translatable by a processor for providing a job server configured for:
receiving a request to execute a job on an endpoint, the endpoint executing an agent, the agent to execute the job and track a job status of the job, the job status indicating one of: the job has not started executing on the endpoint, or the job has completed executing on the endpoint, the job associated with job data on the endpoint; queuing the job request on a job store coupled to the job server; determining that the agent has checked-in; determining that the job queued on the job store is associated with the agent that checked-in; querying the agent on the endpoint to determine the job status of the queued job; if the job status indicates that the job has not started execution on the endpoint, sending a request to the agent on the endpoint to start the job; and if the job status indicates that the job has completed execution on the endpoint, sending a request to receive the associated job data from the agent on the endpoint.
16 . The computer program product according to claim 15 , wherein the request to execute the job is received from a secure server coupled to the job server, wherein the secure server is coupled to the endpoint via a network, wherein the job server determines that the agent has checked-in by receiving a checked-in agent status message from the secure server, and wherein the job server queries the agent regarding the job status via the secure server.
17 . The computer program product according of claim 16 , wherein the job comprises a plurality of jobs, wherein the endpoint comprises a plurality of endpoints, wherein the agent comprises a plurality of agents, each agent executing on one of the plurality of endpoints and each job executing on one of the plurality of endpoints, and wherein the job status of the job executing on one of the plurality of endpoints is received from the agent executing on the one of the plurality of endpoints that has checked-in with the secure server.
18 . The computer program product according to claim 16 , wherein the job comprises a plurality of jobs executing on the endpoint, wherein the job status for each of the plurality of jobs is received by the job server via the secure server, and wherein the job server sends the request to start the job for each job that has not started execution on the endpoint and sends the request to receive the associated job data for each job that has completed execution on the endpoint.
19 . The computer program product of claim 16 , wherein the job server is indirectly coupled to the endpoint and wherein the instructions are further translatable by the processor for:
authenticating, by the secure server, the endpoint.
20 . The computer program product of claim 16 , wherein the agent has an offline status when not executing on the endpoint, or has an online status when executing on the endpoint, the agent checking-in with the secure server when changing from the offline status to the online status.Join the waitlist — get patent alerts
Track US2023032104A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.