Endpoint State Collection via Network-Based Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current endpoint state analysis and scanning systems face issues with redundant requests, connectivity failures, communication latency, resource pressure, software update management, and single points of failure, leading to outdated endpoint state data due to network overhead and concurrency limits.
Innovation Solution
A system and method for collecting endpoint state that initiates communication when network connectivity is established, using a manifest to prioritize data collection, employing delta updates to synchronize endpoint state with a virtualized image, and storing hash values to reduce data size and impact on endpoints, thereby addressing the limitations of existing systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If remote endpoint scanning via dedicated appliance is used, then scanning coverage is improved, but communication latency increases and single point of failure risk increases
Solution Approach 1:
The patent inverts the traditional scanning architecture by placing scanning functionality directly on endpoint devices rather than using remote appliances. Endpoint devices scan their own state locally, eliminating network communication latency while maintaining comprehensive scanning coverage. The centralized server receives only synthesized results rather than raw scan data, reducing network overhead.
2Measurement precision
If frequent endpoint state requests are made, then endpoint state freshness is improved, but network overhead increases and endpoint resource pressure increases
Solution Approach 1:
The patent extracts only the essential scanning results and state changes from endpoints rather than transmitting complete endpoint state data. The centralized server receives synthesized summaries and deltas representing state changes, significantly reducing network overhead while maintaining endpoint state freshness through frequent but lightweight communications.
3Productivity
If agent-based local scanning is used, then scanning speed is improved, but endpoint resource pressure increases and software update management complexity increases
Solution Approach 1:
The patent implements self-service scanning where endpoint devices autonomously perform their own state scanning using built-in capabilities. Each endpoint device independently executes scanning operations, synthesizes results, and transmits them to the centralized server, eliminating the need for complex agent software deployment and update management while maintaining high scanning speed.
4Extent of automation
If remote scanning appliance is used, then centralized control is improved, but single point of failure risk increases and communication latency increases
Solution Approach 1:
The patent segments scanning functionality from centralized control by distributing autonomous scanning capabilities to individual endpoint devices while maintaining centralized result aggregation. Each endpoint device operates independently as a self-contained scanning unit, eliminating the single point of failure associated with remote scanning appliances while preserving centralized visibility through result synthesis on the server.
Data Source
AI summary
The presently described embodiments relate to a novel system and method to collect state as a snapshot from a potentially transient endpoint and transmit the state to a public or private network for storage and processing. This system and method allows for the synchronization and virtualization of the endpoint state image in the network for purposes of processing, analysis, and reporting, including but not limited to endpoint vulnerability auditing.


