Patents by Inventor Ehud DORON

Ehud DORON has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 11381593
    Abstract: A system and method for generating insights on distributed denial of service (DDoS) attacks are provided. The method includes receiving a plurality of data feeds from a plurality of data sources; processing the plurality of received data feeds to generate enriched data sets; and analyzing the enriched data sets to generate insights information about a DDoS attack that have been participated in at least one DDoS attack.
    Type: Grant
    Filed: December 11, 2018
    Date of Patent: July 5, 2022
    Assignee: Radware, Ltd.
    Inventors: Ehud Doron, Yotam Ben Ezra, David Aviv
  • Patent number: 11363044
    Abstract: A method for detecting hypertext transfer protocol secure (HTTPS) flood denial-of-service (DDoS) attacks. The method estimating traffic telemetries of at least ingress traffic directed to a protected entity; providing at least one rate-base feature and at least one rate-invariant feature based on the estimated traffic telemetries, wherein the rate-base feature and the rate-invariant feature demonstrate a normal behavior of HTTPS traffic directed to the protected entity; evaluating the at least one rate-base feature and the at least one rate-invariant feature with respect to at least one baseline to determine whether the behavior of the at least HTTPS traffic indicates a potential HTTPS flood DDoS attack; and causing execution of a mitigation action when an indication of a potential HTTPS flood DDoS attack is determined.
    Type: Grant
    Filed: June 26, 2019
    Date of Patent: June 14, 2022
    Assignee: Radware, Ltd.
    Inventors: Ehud Doron, Lev Medvedovsky, David Aviv, Eyal Rundstein, Ronit Lubitch Greenberg, Avishay Balderman
  • Publication number: 20210281603
    Abstract: An out-of-path defense platform protecting against excessive utilization of a cloud service providing a cloud hosted application comprising a controller communicatively coupled to a detector and a mitigator; wherein the detector receives telemetries from sources that are configured to collect telemetries related to the traffic between end user devices and an edge network that distributes traffic for the cloud hosted application, the telemetries being out-of-path information for traffic to and from the cloud-hosted application, wherein a portion of the telemetries relate to operation of a portion of a cloud computing platform hosting the cloud-hosted application, and detects, using the collected telemetries and a learned normal utilization behavior of each cloud service for the cloud-hosted application, excessive utilization of a cloud service by the cloud hosted application; and wherein the controller, upon detection of the excessive utilization, causes mitigation, by the mitigator, of the excessive utilizati
    Type: Application
    Filed: March 15, 2021
    Publication date: September 9, 2021
    Applicant: RADWARE, LTD.
    Inventors: Ehud DORON, Nir ILANI, David AVIV, Yotam BEN EZRA, Amit BISMUT
  • Patent number: 11089035
    Abstract: A method and system for predicting subsequent cyber-attacks in attack campaigns are provided. The method includes receiving events data related to cyber-attacks occurring in a network during a predefined time window; extracting at least one sequence from the received events data at least one attack vector; generating a sequence signature for each of the at least one extracted sequence; comparing each sequence signature to a representation of historic sequence signatures to determine at least partially matching sequence signature; and based on the matching sequence, determining at least one subsequent cyber-attack in a respective sequence.
    Type: Grant
    Filed: December 11, 2018
    Date of Patent: August 10, 2021
    Assignee: Radware Ltd.
    Inventors: Ehud Doron, Amnon Lotem, Yotam Ben-Ezra, Ami Navon, Nadav Grossaug, Nissim Pariente
  • Publication number: 20210194903
    Abstract: A system and method for detecting anomalous hypertext transfer protocol secure (HTTPS) traffic are provided. The method includes receiving samples of at least rate-base features, wherein the rate-base features demonstrate a normal behavior of at least HTTPS traffic directed to a protected entity; computing a short-term baseline and a long-term baseline based on the received samples, wherein the short-term baseline is adapted to relatively rapid changes in the HTTPS traffic and the long-term baseline is adapted to relatively slow changes in the HTTPS traffic; computing at least one short-term threshold respective of the short-term baseline and at least one long-term threshold respective of the long-term baseline; evaluating each of the at least one threshold against real-time samples of HTTPS traffic to determine whether behavior of the HTTPS traffic is anomalous; and generating alarm when anomaly is detected.
    Type: Application
    Filed: December 19, 2019
    Publication date: June 24, 2021
    Applicant: RADWARE, LTD.
    Inventors: Lev MEDVEDOVSKY, David AVIV, Ehud DORON
  • Publication number: 20210152594
    Abstract: A method and system for protecting cloud-hosted applications against application-layer slow DDoS attacks are provided. The system include a processing circuitry; and a memory connected to the processor, the memory contains instructions that when executed by the processing circuitry, configure the system to: collect telemetries from a plurality of sources deployed in a plurality of public cloud computing platforms, wherein each of the plurality of public cloud computing platforms hosts an instance of a protected cloud-hosted application; provide a set of rate-based and rate-invariant features based on the collected telemetries; evaluate each feature in the set of rate-based and rate-invariant features to determine whether a behavior of each feature and a behavior of the set of rate-based and rate-invariant features indicate a potential application-layer slow DDoS attack; and cause execution of a mitigation action, when an indication of a potential application-layer slow DDoS attack is determined.
    Type: Application
    Filed: December 23, 2020
    Publication date: May 20, 2021
    Applicant: RADWARE, LTD.
    Inventors: Ehud DORON, Nir ILANI, David AVIV, Yotam BEN EZRA, Amit BISMUT, Yuriy ARBITMAN
  • Publication number: 20210099482
    Abstract: A method and system for protecting against quick UDP Internet connection (QUIC) based denial-of-service (DDoS) attacks. The system comprises extracting traffic features from at least traffic directed to a protected entity, wherein the traffic features demonstrate behavior of QUIC user datagram protocol (UDP) traffic directed to the protected entity, wherein the extract traffic features include at least one rate-base feature and at least one rate-invariant feature, and wherein the at least traffic includes QUIC packets; computing at least one baseline for each of the at least one rate-base feature and the at least one rate-invariant feature; and analyzing real-time samples of traffic directed to the protected entity to detect a deviation from each of the at least one computed baseline, wherein the deviation is indicative of a detected QUIC DDoS attack; and causing execution of at least one mitigation action when an indication of the detected QUIC DDoS attack is determined.
    Type: Application
    Filed: December 31, 2019
    Publication date: April 1, 2021
    Applicant: RADWARE, LTD.
    Inventors: Ehud DORON, David AVIV, Eyal RUNDSTEIN, Lev MEDVEDOVSKY
  • Patent number: 10951648
    Abstract: A method, system and a platform for protecting against excessive utilization of at least one cloud service for operation of a cloud-hosted application. The method comprising receiving, at a defense platform deployed out-of-path of traffic between a plurality of end user devices and the cloud-hosted application, telemetries from a plurality of sources, wherein each source is configured to collect telemetries related to at least one of the at least one cloud service; detecting, based on the collected telemetries and a learned normal utilization behavior for the cloud-hosted application, excessive utilization of at least one of the at least one cloud service by the cloud-hosted application; and causing mitigation, at the defense platform, of the excessive utilization of each cloud service upon detection of the excessive utilization of the at least one cloud service by the cloud-hosted application.
    Type: Grant
    Filed: March 29, 2018
    Date of Patent: March 16, 2021
    Assignee: Radware, Ltd.
    Inventors: Ehud Doron, Nir Ilani, David Aviv, Yotam Ben Ezra, Amit Bismut
  • Patent number: 10887341
    Abstract: A method and system for protecting cloud-hosted applications against application-layer slow distributed denial-of-service (DDoS) attacks. The comprising collecting telemetries from a plurality of sources deployed in at least one cloud computing platform hosting a protected cloud-hosted application; providing a set of rate-based and rate-invariant features based on the collected telemetries; evaluating each feature in the set of rate-based and rate-invariant features to determine whether a behavior of each feature and a behavior of the set of rate-based and rate-invariant features indicate a potential application-layer slow DDoS attack; and causing execution of a mitigation action, when an indication of a potential application-layer slow DDoS attack is determined.
    Type: Grant
    Filed: July 24, 2017
    Date of Patent: January 5, 2021
    Assignee: Radware, Ltd.
    Inventors: Ehud Doron, Nir Ilani, David Aviv, Yotam Ben Ezra, Amit Bismut, Yuriy Arbitman
  • Publication number: 20200412750
    Abstract: A method for detecting hypertext transfer protocol secure (HTTPS) flood denial-of-service (DDoS) attacks. The method estimating traffic telemetries of at least ingress traffic directed to a protected entity; providing at least one rate-base feature and at least one rate-invariant feature based on the estimated traffic telemetries, wherein the rate-base feature and the rate-invariant feature demonstrate a normal behavior of HTTPS traffic directed to the protected entity; evaluating the at least one rate-base feature and the at least one rate-invariant feature with respect to at least one baseline to determine whether the behavior of the at least HTTPS traffic indicates a potential HTTPS flood DDoS attack; and causing execution of a mitigation action when an indication of a potential HTTPS flood DDoS attack is determined.
    Type: Application
    Filed: June 26, 2019
    Publication date: December 31, 2020
    Applicant: RADWARE, LTD.
    Inventors: Ehud DORON, Lev MEDVEDOVSKY, David AVIV, Eyal RUNDSTEIN, Ronit LUBITCH GREENBERG, Avishay BALDERMAN
  • Patent number: 10742679
    Abstract: A method and system for controlling multi-tiered mitigation of cyber-attacks.
    Type: Grant
    Filed: October 18, 2018
    Date of Patent: August 11, 2020
    Assignee: Radware, Ltd.
    Inventors: Ehud Doron, David Aviv, Yotam Ben Ezra, Lev Medvedovsky
  • Patent number: 10523693
    Abstract: A system and method for real-time tuning of inference systems based on quality of incoming data. The method comprises: periodically receiving traffic data collected by a plurality of collectors deployed in a network; determining at least a normalized variance of a current sample of the received traffic data; estimating, based in part on the normalized variance, a standard deviation of the received traffic data and a fading coefficient of a baseline filter; determining a current baseline value based on a previous baseline value, the fading coefficient, and the current sample of the traffic data; and dynamically setting at least one membership function of the inference system based in part on the current baseline value and the standard deviation.
    Type: Grant
    Filed: April 10, 2017
    Date of Patent: December 31, 2019
    Assignee: Radware, Ltd.
    Inventors: Lev Medvedovsky, David Aviv, Ehud Doron, Asaf Oron, Yuriy Arbitman
  • Patent number: 10375158
    Abstract: A system and method for managing an application delivery controller (ADC) cluster including a plurality of ADCs are provided. The method includes creating a hash table including a plurality of buckets, wherein a number of the plurality of buckets is a multiple of a maximum number of active ADCs that can be supported by the ADC cluster; allocating, to each active ADC of the ADC cluster, one of the plurality of buckets; and instructing at least one network element to distribute traffic to and from the active ADCs based on the hash table.
    Type: Grant
    Filed: July 1, 2016
    Date of Patent: August 6, 2019
    Assignee: RADWARE, LTD.
    Inventors: Benny Rochwerger, Ehud Doron, Kobi Samoray
  • Publication number: 20190199746
    Abstract: A system and method for reducing a time to mitigate distributed denial of service (DDoS) attacks are provided. The method includes receiving a plurality of attack feeds on at least one protected object in a secured environment; analyzing the plurality of attack feeds to determine characteristics of a DDoS attack against the secure environment; determining a set of optimal mitigation resources assigned to the secured environment; selecting, based on the set of optimal mitigation resources and the attack characteristics, at least one optimal workflow scheme; and initiating a proactive mitigation action by setting each mitigation resource in the set of optimal mitigation resources according to the selected optimal workflow scheme.
    Type: Application
    Filed: December 20, 2018
    Publication date: June 27, 2019
    Applicant: RADWARE, LTD.
    Inventors: Ehud DORON, Yotam BEN EZRA, David AVIV
  • Publication number: 20190182274
    Abstract: A method and system for predicting subsequent cyber-attacks in attack campaigns are provided. The method includes receiving events data related to cyber-attacks occurring in a network during a predefined time window; extracting at least one sequence from the received events data at least one attack vector; generating a sequence signature for each of the at least one extracted sequence; comparing each sequence signature to a representation of historic sequence signatures to determine at least partially matching sequence signature; and based on the matching sequence, determining at least one subsequent cyber-attack in a respective sequence.
    Type: Application
    Filed: December 11, 2018
    Publication date: June 13, 2019
    Applicant: RADWARE, LTD.
    Inventors: Ehud DORON, Amnon LOTEM, Yotam BEN-EZRA, Ami NAVON, Nadav GROSSAUG, Nissim PARIENTE
  • Publication number: 20190182266
    Abstract: A system and method for out-of-path detection of cyber-attacks are provided. The method includes receiving, by a detector, a plurality of data feeds from a plurality of data sources, wherein the detector is communicatively connected to the plurality of data sources; processing, by the detector, the plurality of received data feeds to generate enriched Flow data sets; analyzing the enriched Flow data sets to detect a potential cyber-attack; and upon detection of a potential cyber-attack, providing indication to each network entity of the network entities that is under attack.
    Type: Application
    Filed: December 6, 2018
    Publication date: June 13, 2019
    Applicant: RADWARE, LTD.
    Inventors: Ehud DORON, Yotam BEN EZRA, David AVIV
  • Publication number: 20190182291
    Abstract: A system and method for generating insights on distributed denial of service (DDoS) attacks are provided. The method includes receiving a plurality of data feeds from a plurality of data sources; processing the plurality of received data feeds to generate enriched data sets; and analyzing the enriched data sets to generate insights information about a DDoS attack that have been participated in at least one DDoS attack.
    Type: Application
    Filed: December 11, 2018
    Publication date: June 13, 2019
    Applicant: RADWARE, LTD.
    Inventors: Ehud DORON, Yotam BEN EZRA, David AVIV
  • Publication number: 20190052671
    Abstract: A method and system for controlling multi-tiered mitigation of cyber-attacks.
    Type: Application
    Filed: October 18, 2018
    Publication date: February 14, 2019
    Applicant: RADWARE, LTD.
    Inventors: Ehud DORON, David AVIV, Yotam BEN EZRA, Lev MEDVEDOVSKY
  • Patent number: 10129297
    Abstract: A method and system for controlling multi-tiered mitigation of cyber-attacks.
    Type: Grant
    Filed: September 18, 2017
    Date of Patent: November 13, 2018
    Assignee: Radware, Ltd.
    Inventors: Ehud Doron, David Aviv, Yotam Ben Ezra, Lev Medvedovsky
  • Patent number: 10110485
    Abstract: A method and system for mitigating of cyber-attacks in a software defined network (SDN) are presented. The method comprises operating a central controller and the SDN in a peace mode; monitoring traffic addressed to at least one destination server to detect at least an attack performed against the at least one destination server; switching an operation of the central controller to an attack mode, upon detection of an attack against the at least one destination server; and instructing, by the central controller, network elements of the SDN to divert all suspicious incoming traffic addressed to the at least one destination server to a security server, thereby mitigating the detected attack.
    Type: Grant
    Filed: June 2, 2015
    Date of Patent: October 23, 2018
    Assignee: Radware, Ltd.
    Inventors: Avi Chesla, Ehud Doron