Patents by Inventor Ilya Fainberg

Ilya Fainberg has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 11811612
    Abstract: Systems and methods for monitoring devices on a network are describes. An indication of one or more active devices coupled to a network at an end of a time interval is received. Network traffic data associated with the network is received and one or more additional devices coupled to the network during the time interval that were not included in the indication of the one or more active devices coupled to the network at the end of the time interval are determined based on the network traffic data.
    Type: Grant
    Filed: January 21, 2022
    Date of Patent: November 7, 2023
    Assignee: FORESCOUT TECHNOLOGIES, INC.
    Inventors: Ilya Fainberg, Anderson Lam, Mihael Sudakovitch
  • Publication number: 20230269140
    Abstract: Systems, methods, and related technologies for segmentation management are described. In certain aspects, an entity communicatively coupled to a network is selected and one or more characteristics of the entity may be determined. A segmentation policy may be selected based on the one or more characteristics of the entity and one or more tags to be assigned to the entity based on the segmentation policy may be determined. A zone for the entity based on the one or more tags may be determined and one or more enforcement points associated with the zone for the entity may be determined. One or more enforcement actions may then be assigned to the one or more enforcement points based on the zone associated with the entity.
    Type: Application
    Filed: April 27, 2023
    Publication date: August 24, 2023
    Inventors: Ilya Fainberg, Mark Kurman, David Bar
  • Patent number: 11677627
    Abstract: Systems, methods, and related technologies for segmentation management are described. In certain aspects, an entity communicatively coupled to a network is selected and one or more characteristics of the entity may be determined. A segmentation policy may be selected based on the one or more characteristics of the entity and one or more tags to be assigned to the entity based on the segmentation policy may be determined. A zone for the entity based on the one or more tags may be determined and one or more enforcement points associated with the zone for the entity may be determined. One or more enforcement actions may then be assigned to the one or more enforcement points based on the zone associated with the entity.
    Type: Grant
    Filed: June 29, 2018
    Date of Patent: June 13, 2023
    Assignee: FORESCOUT TECHNOLOGIES, INC.
    Inventors: Ilya Fainberg, Mark Kurman, David Bar
  • Publication number: 20230020094
    Abstract: Systems, methods, and related technologies for access control management are described. The access control management may be customized for an entity and be configured on an enforcement point closest to the entity. In certain aspects, an entity communicatively coupled to a network is selected and one or more characteristics of the entity determined. An access policy may be selected based on the one or more characteristics of the entity and one or more enforcement points closest to the entity determined. One or more access rules to be assigned to the one or more enforcement points based on the access policy may be determined, wherein the one or more access rules are specific to the entity based on the one or more characteristics of the entity. The one or more access rules assigned to or configured on the one or more enforcement points closest to the entity are assigned.
    Type: Application
    Filed: September 16, 2022
    Publication date: January 19, 2023
    Inventors: Ilya Fainberg, Tomer Reisner
  • Publication number: 20220385634
    Abstract: Systems, methods, and related technologies for segmentation management are described. The segmentation management may include visualization, configuration including translation, simulation, or a combination thereof of one or more segmentation policies. In certain aspects, a segmentation policy is accessed and a segmentation rule is determined based on the segmentation policy, wherein the segmentation rule is based on a characteristic of an entity determined without the use of an agent. An enforcement point associated with the segmentation rule may be determined, where the enforcement point is communicatively coupled to a network. The segmentation rule may be translated into a configuration associated with the enforcement point and the configuration communicated to the enforcement point.
    Type: Application
    Filed: August 8, 2022
    Publication date: December 1, 2022
    Inventor: Ilya Fainberg
  • Patent number: 11463482
    Abstract: Systems, methods, and related technologies for access control management are described. The access control management may be customized for an entity and be configured on an enforcement point closest to the entity. In certain aspects, an entity communicatively coupled to a network is selected and one or more characteristics of the entity determined. An access policy may be selected based on the one or more characteristics of the entity and one or more enforcement points closest to the entity determined. One or more access rules to be assigned to the one or more enforcement points based on the access policy may be determined and the one or more access rules assigned to or configured on the one or more enforcement points closest to the entity.
    Type: Grant
    Filed: March 13, 2019
    Date of Patent: October 4, 2022
    Assignee: FORESCOUT TECHNOLOGIES, INC.
    Inventors: Ilya Fainberg, Tomer Reisner
  • Publication number: 20220255960
    Abstract: Systems, methods, and related technologies including media access control (MAC) address spoofing detection are described. The MAC address spoofing detection and response may include accessing a first MAC address associated with a first communication on a first port of a first network device and accessing a second MAC address associated with a second communication on a second port of a second network device. Whether the first MAC address and the second MAC address match may be determined. Information associated with a third communication associated with the first MAC address on the first port of the first network device and information associated with a fourth communication associated with the second MAC address on the second port of the second network device may be accessed. An action may be performed associated with the second port of the second network device based on the second MAC address matching the first MAC address.
    Type: Application
    Filed: April 28, 2022
    Publication date: August 11, 2022
    Inventors: Ilya Fainberg, Abdelhamid Masarwa, Oren Nechushtan, Oded Comay
  • Patent number: 11411822
    Abstract: Systems, methods, and related technologies for segmentation management are described. The segmentation management may include visualization, configuration including translation, simulation, or a combination thereof of one or more segmentation policies. In certain aspects, a segmentation policy is accessed and a segmentation rule is determined based on the segmentation policy. An enforcement point associated with the segmentation rule may be determined, where the enforcement point is communicatively coupled to a network. The segmentation rule may be translated into a configuration associated with the enforcement point and the configuration communicated to the enforcement point.
    Type: Grant
    Filed: September 27, 2018
    Date of Patent: August 9, 2022
    Assignee: Forescout Technologies, Inc.
    Inventor: Ilya Fainberg
  • Patent number: 11349867
    Abstract: Systems, methods, and related technologies including media access control (MAC) address spoofing detection are described. The MAC address spoofing detection and response may include accessing a first MAC address associated with a first communication on a first port of a first network device and accessing a second MAC address associated with a second communication on a second port of a second network device. Whether the first MAC address and the second MAC address match may be determined. Information associated with a third communication associated with the first MAC address on the first port of the first network device and information associated with a fourth communication associated with the second MAC address on the second port of the second network device may be accessed. An action may be performed associated with the second port of the second network device based on the second MAC address matching the first MAC address.
    Type: Grant
    Filed: December 31, 2018
    Date of Patent: May 31, 2022
    Assignee: Forescout Technologies, Inc.
    Inventors: Ilya Fainberg, Abdelhamid Masarwa, Oren Nechushtan, Oded Comay
  • Publication number: 20220150126
    Abstract: Systems and methods for monitoring devices on a network are describes. An indication of one or more active devices coupled to a network at an end of a time interval is received. Network traffic data associated with the network is received and one or more additional devices coupled to the network during the time interval that were not included in the indication of the one or more active devices coupled to the network at the end of the time interval are determined based on the network traffic data.
    Type: Application
    Filed: January 21, 2022
    Publication date: May 12, 2022
    Inventors: Ilya Fainberg, Anderson Lam, Mihael Sudakovitch
  • Publication number: 20220123996
    Abstract: Systems, methods, and related technologies for segmentation management are described. The segmentation management may include visualization, configuration, simulation, or a combination thereof of one or more segmentation policies. In certain aspects, a plurality of segmentation rules are accessed and one or more characteristics of a plurality of entities communicatively coupled to a network are determined. A plurality of groups may be determined based on at least one characteristic of the one or more characteristics, where each group comprises at least one entity of the plurality of entities. A first group and a second group from the plurality of groups may be selected and one or more segmentation rules associated with the first group determined. One or more segmentation rules associated with the second group may be determined.
    Type: Application
    Filed: December 31, 2021
    Publication date: April 21, 2022
    Inventors: Ilya Fainberg, Yafit Maor, Amir Olswang
  • Patent number: 11271812
    Abstract: Systems, methods, and related technologies for segmentation management are described. The segmentation management may include visualization, configuration, simulation, or a combination thereof of one or more segmentation policies. In certain aspects, a plurality of segmentation rules are accessed and one or more characteristics of a plurality of entities communicatively coupled to a network are determined. A plurality of groups may be determined based on at least one characteristic of the one or more characteristics, where each group comprises at least one entity of the plurality of entities. A first group and a second group from the plurality of groups may be selected and one or more segmentation rules associated with the first group determined. One or more segmentation rules associated with the second group may be determined.
    Type: Grant
    Filed: September 27, 2018
    Date of Patent: March 8, 2022
    Assignee: Forescout Technologies, inc.
    Inventors: Ilya Fainberg, Yafit Maor, Amir Olswang
  • Patent number: 11240114
    Abstract: Systems, methods, and related technologies for device monitoring are described. In certain aspects, network traffic data is analyzed to determine one or more devices associated with a network. The network may be a remote network. The network traffic data may further be used to determine one or more non-active devices associated with the network.
    Type: Grant
    Filed: December 27, 2019
    Date of Patent: February 1, 2022
    Assignee: FORESCOUT TECHNOLOGIES, INC.
    Inventors: Ilya Fainberg, Anderson Lam, Mihael Sudakovitch
  • Publication number: 20210099473
    Abstract: Systems, methods, and related technologies for determining an anomaly based on properties associated with an entity are described. The determination of an anomaly associated with an entity may include accessing network traffic from a network and storing a first value of a property associated with an entity communicatively coupled to the network. The first value of the property is based on the network traffic. Additional network traffic associated with the entity may be accessed and a second value of the property determined based on the additional network traffic. Whether the first value of the property does not match the second value of the property may be determined and in response to the first value of the property not matching the second value of the property, an indicator that an anomaly has detected may be stored. An action may be performed based on determination of an anomaly.
    Type: Application
    Filed: September 26, 2019
    Publication date: April 1, 2021
    Inventors: Ilya Fainberg, Tomer Iyar, Abdelhamid Masarwa
  • Publication number: 20200296139
    Abstract: Systems, methods, and related technologies for access control management are described. The access control management may be customized for an entity and be configured on an enforcement point closest to the entity. In certain aspects, an entity communicatively coupled to a network is selected and one or more characteristics of the entity determined. An access policy may be selected based on the one or more characteristics of the entity and one or more enforcement points closest to the entity determined. One or more access rules to be assigned to the one or more enforcement points based on the access policy may be determined and the one or more access rules assigned to or configured on the one or more enforcement points closest to the entity.
    Type: Application
    Filed: March 13, 2019
    Publication date: September 17, 2020
    Inventors: Ilya Fainberg, Tomer Reisner
  • Publication number: 20200213352
    Abstract: Systems, methods, and related technologies including media access control (MAC) address spoofing detection are described. The MAC address spoofing detection and response may include accessing a first MAC address associated with a first communication on a first port of a first network device and accessing a second MAC address associated with a second communication on a second port of a second network device. Whether the first MAC address and the second MAC address match may be determined. Information associated with a third communication associated with the first MAC address on the first port of the first network device and information associated with a fourth communication associated with the second MAC address on the second port of the second network device may be accessed. An action may be performed associated with the second port of the second network device based on the second MAC address matching the first MAC address.
    Type: Application
    Filed: December 31, 2018
    Publication date: July 2, 2020
    Inventors: Ilya Fainberg, Abdelhamid Masarwa, Oren Nechushtan, Oded Comay
  • Publication number: 20200136919
    Abstract: Systems, methods, and related technologies for device monitoring are described. In certain aspects, network traffic data is analyzed to determine one or more devices associated with a network. The network may be a remote network. The network traffic data may further be used to determine one or more non-active devices associated with the network.
    Type: Application
    Filed: December 27, 2019
    Publication date: April 30, 2020
    Inventors: Ilya Fainberg, Anderson Lam, Mihael Sudakovitch
  • Patent number: 10560336
    Abstract: Systems, methods, and related technologies for device monitoring are described. In certain aspects, network traffic data is analyzed to determine one or more devices associated with a network. The network may be a remote network. The network traffic data may further be used to determine one or more non-active devices associated with the network.
    Type: Grant
    Filed: January 31, 2017
    Date of Patent: February 11, 2020
    Assignee: FORESCOUT TECHNOLOGIES, INC.
    Inventors: Ilya Fainberg, Anderson Lam, Mihael Sudakovitch
  • Publication number: 20200007395
    Abstract: Systems, methods, and related technologies for segmentation management are described. In certain aspects, an entity communicatively coupled to a network is selected and one or more characteristics of the entity may be determined. A segmentation policy may be selected based on the one or more characteristics of the entity and one or more tags to be assigned to the entity based on the segmentation policy may be determined. A zone for the entity based on the one or more tags may be determined and one or more enforcement points associated with the zone for the entity may be determined. One or more enforcement actions may then be assigned to the one or more enforcement points based on the zone associated with the entity.
    Type: Application
    Filed: June 29, 2018
    Publication date: January 2, 2020
    Inventors: Ilya Fainberg, Mark Kurman, David Bar
  • Publication number: 20200007397
    Abstract: Systems, methods, and related technologies for segmentation management are described. The segmentation management may include visualization, configuration including translation, simulation, or a combination thereof of one or more segmentation policies. In certain aspects, a segmentation policy is accessed and a segmentation rule is determined based on the segmentation policy. An enforcement point associated with the segmentation rule may be determined, where the enforcement point is communicatively coupled to a network. The segmentation rule may be translated into a configuration associated with the enforcement point and the configuration communicated to the enforcement point.
    Type: Application
    Filed: September 27, 2018
    Publication date: January 2, 2020
    Inventor: Ilya Fainberg