SYSTEM AND METHOD FOR PERFORMING REMOTE SECURITY ASSESSMENT OF FIREWALLED COMPUTER
First Claim
1. A method of conducting a scan on an endpoint system across an open computer network, the endpoint system being protected from the open computer network by a firewall, the method comprising:
- providing a scanner engine in a computer server in communication with the open computer network;
providing a scanner agent installed on the endpoint system in communication with the open computer network through the firewall;
establishing a secure layer connection between the scanner engine and the scanner agent without requiring credentialed access through an open firewall port;
collecting data regarding the endpoint system using the scanner agent, the collected data including at least one of system configuration information, system services information, or file system information;
receiving the collected data from the scanner agent at the scanner engine via the secure layer connection;
analyzing the collected data with the scanner engine to assess a current security vulnerability posture of the endpoint system, and determining any updates for the endpoint system from the analysis; and
sending the updates via the secure layer connection to the scanner agent for installation on the endpoint system.
1 Assignment
0 Petitions
Accused Products
Abstract
Methods and systems for scanning an endpoint terminal across an open computer network are disclosed. An exemplary method includes providing a scanner engine in a computer server in communication with an open computer network, and establishing a secure connection across the open computer network between the scanner engine and a scanner agent installed on the endpoint terminal in communication with the open computer network. Commands for collecting data regarding the endpoint terminal are sent from the scanner engine across the secure connection to the scanner agent. The scanner engine then receives the collected data from the scanner agent across the secure connection, analyzes the data to assess a current posture of the endpoint terminal, and determines any updates for the endpoint terminal from the analysis. Updates are sent across the secure connection to the scanner agent for installation on the endpoint terminal, and the secure connection may then be terminated.
24 Citations
32 Claims
-
1. A method of conducting a scan on an endpoint system across an open computer network, the endpoint system being protected from the open computer network by a firewall, the method comprising:
-
providing a scanner engine in a computer server in communication with the open computer network; providing a scanner agent installed on the endpoint system in communication with the open computer network through the firewall; establishing a secure layer connection between the scanner engine and the scanner agent without requiring credentialed access through an open firewall port; collecting data regarding the endpoint system using the scanner agent, the collected data including at least one of system configuration information, system services information, or file system information; receiving the collected data from the scanner agent at the scanner engine via the secure layer connection; analyzing the collected data with the scanner engine to assess a current security vulnerability posture of the endpoint system, and determining any updates for the endpoint system from the analysis; and sending the updates via the secure layer connection to the scanner agent for installation on the endpoint system. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A system for conducting a scan on an endpoint system across an open computer network, the endpoint system being protected from the open computer network by a firewall, the system comprising:
-
a computer server in communication with the open computer network, wherein the computer server comprises a scanner engine; a scanner agent installed on the endpoint system in communication with the open computer network through the firewall; and a secure layer connection established between the scanner engine and the scanner agent without requiring credentialed access through an open firewall port; wherein the scanner agent is configurable to collect data regarding the endpoint system, the collected data including at least one of system configuration information, system services information, or file system information; wherein the scanner engine is configurable to; receive data via the secure layer connection regarding the endpoint system collected by the scanner agent; analyze the collected data to assess a current security vulnerability posture of the endpoint system and determine any updates for the endpoint system from the analysis, and send the updates via the secure layer connection to the scanner agent for installation on the endpoint system. - View Dependent Claims (9, 10, 11, 12, 13, 14, 15)
-
-
16. A method of conducting a scan on an endpoint system across an open computer network, the endpoint system being protected from the open computer network by a firewall, the method comprising:
-
providing a scanner engine in a computer server in communication with the open computer network; establishing a secure layer connection across the open computer network between the scanner engine and a scanner agent without requiring credentialed access through an open firewall port, the scanner agent installed on the endpoint system in communication with the open computer network through the firewall; sending commands for collecting data regarding the endpoint system from the scanner engine via the secure layer connection to the scanner agent, the collected data including at least one of system configuration information, system services information, or file system information; receiving the collected data from the scanner agent via the secure layer connection to the scanner engine; analyzing the collected data with the scanner engine to assess a current security vulnerability posture of the endpoint system, and determining any updates for the endpoint system from the analysis; sending the updates via the secure layer connection to the scanner agent for installation on the endpoint system; and terminating the secure layer connection after the updates are received by the endpoint system. - View Dependent Claims (17, 18, 19, 20, 21, 22, 23)
-
-
24. A system for conducting a scan on an endpoint system across an open computer network, the endpoint system being protected from the open computer network by a firewall, the system comprising:
-
a computer server in communication with the open computer network, wherein the computer server comprises a scanner engine; a scanner agent installed on the endpoint system in communication with the open computer network through the firewall; a secure layer connection established between the scanner engine and the scanner agent without requiring credentialed access through an open firewall port; and wherein the scanner agent is configurable to collect data regarding the endpoint system, the collected data including at least one of system configuration information, system services information, or file system information; wherein the scanner engine is configurable to; send commands via the secure layer connection for collecting data regarding the endpoint system to the scanner agent, receive the collected data from the scanner agent via the secure connection, analyze the collected data to assess a current security vulnerability posture of the endpoint system and determining any update for the endpoint system from the analysis, and send the updates via the secure connection to the scanner agent for installation on the endpoint system. - View Dependent Claims (25, 26, 27, 28, 29, 30, 31)
-
-
32. A method of conducting a scan on an endpoint system across an open computer network, the endpoint system being protected from the open computer network by a firewall, the method comprising:
-
providing a scanner engine in a computer server in communication with the open computer network; providing a scanner agent installed on the endpoint system in communication with the scanner engine through the open computer network a secure layer connection established between the scanner engine and the scanner agent without requiring credentialed access through an open firewall port; receiving, at the scanner agent and via the secure layer connection, commands from the scanner engine to access an operating system of the endpoint system to collect data regarding the endpoint system; collecting, by the scanner agent, data regarding the endpoint system, the collected data including at least one of system configuration information, system services information, or file system information; receiving, at the scanner engine and via the secure layer connection, the collected data from the scanner agent; analyzing, at the scanner engine, the collected data to assess a current security vulnerability posture of the endpoint system, and determining any updates for the endpoint system from the analysis; and sending the updates via the secure layer connection to the scanner agent for installation on the endpoint system.
-
Specification