Patents Assigned to Varonis Systems, Inc.
  • Publication number: 20120271855
    Abstract: In a hierarchical access permissions environment, a method for enabling efficient management of project-wise permissions including maintaining project-wise lists of network objects, access permissions to which cannot be managed together via a hierarchical folder structure and employing the project-wise lists of network objects to make project-wise changes in access permissions to the network objects without the need to individually modify access permissions to individual ones of the network objects.
    Type: Application
    Filed: November 23, 2011
    Publication date: October 25, 2012
    Applicant: VARONIS SYSTEMS, INC.
    Inventors: Yakov FAITELSON, Ohad KORKUS, Ophir KRETZER-KATZIR
  • Patent number: 8239925
    Abstract: Methods and systems are provided for controlling access to a file system. A record of actual accesses by users of the file system is maintained. Before a user is removed from a set of users or before a privilege for a set of users to access a data element is removed, it is determined whether the actual recorded accesses of the user are allowed by residual access permissions that would remain after implementing the proposed removal of access permission. An error condition is generated if the proposed removal of the access permission would have prevented at least one of the actual accesses. In another aspect of the invention, the system determines if the users would have alternate access to the storage element following implementation of the proposal.
    Type: Grant
    Filed: April 26, 2007
    Date of Patent: August 7, 2012
    Assignee: Varonis Systems, Inc.
    Inventors: Yakov Faitelson, Ohad Korkus, Ophir Kretzer
  • Publication number: 20110010758
    Abstract: A method for ascertaining access permissions of users to computer resources on a storage unit, the method including grouping users into a plurality of user groups wherein all members of at least one of the user groups have at least nearly identical user/resource access permissions to the computer resources, grouping resources into a plurality of resource groups wherein all members of at least one of the resource groups have at least nearly identical resource/user access permissions, ascertaining whether a given user is a member of a user group, if the given user is a member of a user group, ascribing to the given user the user/resource access permissions of the user group, ascertaining whether a given resource is a member of a resource group, and if the given resource is a member of a resource group, ascribing to the given resource the resource/user access permissions of the resource group.
    Type: Application
    Filed: July 7, 2009
    Publication date: January 13, 2011
    Applicant: VARONIS SYSTEMS,INC.
    Inventors: Yakov FAITELSON, Ohad KORKUS, Yzhar KEYSAR
  • Publication number: 20090265780
    Abstract: On-line and computationally efficient methods and systems are provided for back resolving path names of files from inode numbers during data access request processing. As a result, a near real-time recording of data access events is achieved, including identification of the user who performed the access, and the full path name of the data object that was accessed. In a typical application, access events are collected for use in access control of storage elements in complex organizational file systems.
    Type: Application
    Filed: April 21, 2008
    Publication date: October 22, 2009
    Applicant: Varonis Systems Inc.
    Inventors: Ohad Korkus, Yakov Faitelson, Ophir Kretzer, David Bass, Yizhar Keysar
  • Patent number: 7555482
    Abstract: Methods and systems are provided for evaluating atypical user data access activities within the scope of an automatically generated file security policy in organizations with multiple diverse access control models and multiple diverse file server protocols. The system monitors access to storage elements within the network. The recorded data traffic is analyzed to assess simultaneous data access groupings and user groupings, which reflect the actual organizational structure. The learned structure is then transformed into a dynamic file security policy, which is constantly adapted to organizational changes over time. The system provides a decision assistance interface for tracking abnormal user behavior.
    Type: Grant
    Filed: December 7, 2006
    Date of Patent: June 30, 2009
    Assignee: Varonis Systems, Inc.
    Inventor: Ohad Korkus
  • Publication number: 20090119298
    Abstract: Queries regarding access permissions of users and rights to directories in a complex enterprise are executed in near realtime, using lookups to tables that form a condensed database maintained for each file server. User information is condensed by arranging users in user groups having common data access rights. Directory permissions storage is condensed by showing only distinctive permissions to a directory in a table entry, and referencing inherited permissions of parent directories. The tables indicate recursive and ancestral relationships among the user groups and directories. They are developed and updated in advance of any queries. A consolidated view of the query results is presented on a single display screen. Using the tables results can be obtained without exhaustive searches of large file system tables.
    Type: Application
    Filed: November 6, 2007
    Publication date: May 7, 2009
    Applicant: VARONIS SYSTEMS INC.
    Inventors: Yakov Faitelson, Ohad Korkus, Ophir Kretzer