Patents Assigned to Radware Ltd.
  • Publication number: 20120136697
    Abstract: A system for computing an optimal deployment of at least one web application in a multi-datacenter system comprising a collector for collecting performance measurements with regard to a web application executed in the multi-datacenter system and grouping the performance measurements according to locations of a plurality of clients accessing the web application; a data repository for maintaining at least a performance table including at least the performance measurements grouped according to the plurality of client locations and a service level agreement (SLA) guaranteed to clients in the plurality of client locations; and an analyzer for processing at least information stored in the performance table for generating a recommendation on an optimal deployment of the web application in at least one combination of datacenters in the multi-datacenter system by computing an expected SLA that can be guaranteed to the clients in each combination of datacenters.
    Type: Application
    Filed: May 9, 2011
    Publication date: May 31, 2012
    Applicant: Radware, Ltd.
    Inventors: Amir Peles, Shy Marom
  • Publication number: 20120102541
    Abstract: A system for generating a security policy for protecting an application-layer entity. The system comprises a security sitemap generator for generating a security sitemap of a protected application-layer entity, the security sitemap is stored in a first repository connected to the security sitemap generator; and a policy builder for generating a security policy for the application-layer entity based on the security sitemap, the security policy is stored in a second repository connected to the policy builder, wherein the security policy includes a plurality of enforcement rules for at least one of a resource, a group of resources, and a client-side input parameter of at least a portion of the protected application-layer entity.
    Type: Application
    Filed: October 25, 2010
    Publication date: April 26, 2012
    Applicant: RADWARE, LTD.
    Inventors: Michael Groskop, Roy Zisapel
  • Publication number: 20120071131
    Abstract: A method for profiling data communication activity of users of mobile devices, comprises sniffing traffic flows between a mobile device and the Internet through a cellular network; extracting a plurality of traffic attributes included in the traffic flows and associated with the mobile device; logging the extracted plurality of traffic attributes; analyzing the plurality of traffic attributes for generating a user profile for a user of the mobile device based on the plurality of traffic attributes, wherein the user profile includes at least one of an advertising targeted user profile and a security targeted user profile; and sharing information and alerts related to the generated user profile with at least one external system.
    Type: Application
    Filed: September 20, 2011
    Publication date: March 22, 2012
    Applicant: RADWARE, LTD.
    Inventors: Roy ZISAPEL, Amir PELES, Avi CHESLA
  • Patent number: 7984148
    Abstract: A method for load balancing requests on a network, the method including receiving a request from a requester having a requester network address at a first load balancer having a first load balancer network address, the request having a source address indicating the requestor network address and a destination address indicating the first load balancer network address, forwarding the request from the first load balancer to a second load balancer at a triangulation network address, the request source address indicating the requester network address and the destination address indicating the triangulation network address, the triangulation network address being associated with the first load balancer network address, and sending a response from the second load balancer to the requestor at the requestor network address, the response having a source address indicating the first load balancer network address associated with the triangulation network address and a destination address indicating the first requestor ne
    Type: Grant
    Filed: November 10, 2003
    Date of Patent: July 19, 2011
    Assignee: Radware Ltd.
    Inventors: Roy Zisapel, Amir Peless
  • Patent number: 7953973
    Abstract: Methods, systems, and computer program products for passively routing secure socket layer (SSL) encoded network traffic are disclosed. According to one aspect, a method includes passively receiving a copy of SSL encoded network traffic. Further, the method includes passively parsing the received network traffic and generating an identical copy of the network traffic such that the network traffic is not decrypted and without interfering with the network traffic. A target output network device can be selected for transmission of the identical copy of the network traffic. The identical copy of the network traffic can be transmitted from the selected target output network device.
    Type: Grant
    Filed: January 19, 2007
    Date of Patent: May 31, 2011
    Assignee: Radware Ltd.
    Inventors: James Frederick Beam, Byron Lee Hargett, Douglas Wayne Hester, Ricky G. Millham, Jennifer Justina Short, Garth Douglas Somerville, Jason Moore Walker, Virgil Montgomery Wall, Robert Edward Ward
  • Patent number: 7836496
    Abstract: A method for protecting a network from an attack includes measuring a property of traffic entering the network, and analyzing the property using at least one fuzzy logic algorithm in order to detect the attack.
    Type: Grant
    Filed: October 24, 2007
    Date of Patent: November 16, 2010
    Assignee: Radware Ltd.
    Inventors: Avi Chesla, Lev Medvedovsky, Abraham Elboim
  • Patent number: 7769994
    Abstract: A secure access system is used to connect an internal network, such as a private LAN, to an external network, such as the Internet. The system is provided with internal and external gateways, for connecting to the respective networks, as well as an inspection evaluator, content inspector, internal certificate authority, internal SSL terminator and external SSL initiator. Packets routed through the access system are inspected before they are forwarded from one gateway to the other, except those packets of designated users of the internal network which are directly forwarded without inspection. Encrypted packets received by the access system are decrypted, inspected, and then re-encrypted before they are forwarded.
    Type: Grant
    Filed: August 3, 2004
    Date of Patent: August 3, 2010
    Assignee: Radware Ltd.
    Inventor: Amir Peles
  • Patent number: 7738469
    Abstract: In a communications network, a virtual rack having service modules for performing network services is provided. A pinhole that corresponds to a plurality of the service modules is created. Data packets are directed to a service processor in response to matching the data packets to the pinhole. For connection class offload, using the acceleration processor to match the connection class pinhole to the data packets and creating connection class sessions that are used for processing subsequent packets of the connection.
    Type: Grant
    Filed: June 4, 2008
    Date of Patent: June 15, 2010
    Assignee: Radware Ltd.
    Inventors: Praveen Shekokar, Manoj Sharma, Badari Narayana, Ratnarekha Singamsetty, Mahesh Kumar
  • Patent number: 7681235
    Abstract: A method for protecting a network from an attack includes measuring a property of traffic entering the network, and analyzing the property using at least one fuzzy logic algorithm in order to detect the attack.
    Type: Grant
    Filed: May 19, 2003
    Date of Patent: March 16, 2010
    Assignee: Radware Ltd.
    Inventors: Avi Chesla, Lev Medvedovsky, Abraham Elboim
  • Patent number: 7624084
    Abstract: A system and method to detect and mitigate denial of service and distributed denial of service HTTP “page” flood attacks. Detection of attack/anomaly is made according to multiple traffic parameters including rate-based and rate-invariant parameters in both traffic directions. Prevention is done according to HTTP traffic parameters that are analyzed once a traffic anomaly is detected. This protection includes a differential adaptive mechanism that tunes the sensitivity of the anomaly detection engine. The decision engine is based on a combination between fuzzy logic inference systems and statistical thresholds. A “trap buffer” characterizes the attack to allow an accurate mitigation according to the source IP(s) and the HTTP request URL's that are used as part of the attack. Mitigation is controlled through a feedback mechanism that tunes the level of rate limit factors that are needed in order to mitigate the attack effectively while letting legitimate traffic to pass.
    Type: Grant
    Filed: October 9, 2007
    Date of Patent: November 24, 2009
    Assignee: Radware, Ltd.
    Inventor: Avi Chesla
  • Patent number: 7617170
    Abstract: A system and method to detect and mitigate denial of service and distributed denial of service HTTP “page” flood attacks. Detection of attack/anomaly is made according to multiple traffic parameters including rate-based and rate-invariant parameters in both traffic directions. Prevention is done according to HTTP traffic parameters that are analyzed once a traffic anomaly is detected. This protection includes a differential adaptive mechanism that tunes the sensitivity of the anomaly detection engine. The decision engine is based on a combination between fuzzy logic inference systems and statistical thresholds. A “trap buffer” characterizes the attack to allow an accurate mitigation according to the source IP(s) and the HTTP request URL's that are used as part of the attack. Mitigation is controlled through a feedback mechanism that tunes the level of rate limit factors that are needed in order to mitigate the attack effectively while letting legitimate traffic to pass.
    Type: Grant
    Filed: October 9, 2007
    Date of Patent: November 10, 2009
    Assignee: Radware, Ltd.
    Inventor: Avi Chesla
  • Publication number: 20090265467
    Abstract: A method and system for load balancing over a cluster of authentication, authorization and accounting (AAA) servers. The method performs a distribution of AAA requests among AAA servers having an active AAA connection with an AAA client. The method includes establishing TCP connections with a plurality of AAA servers, using a TCP connection request received from at least one AAA client; opening AAA connections with a plurality of AAA servers, using an AAA connection request received from at least one AAA client, and distributing AAA requests to AAA servers with an active AAA connection according to a predefined load balancing algorithm. The invention is further capable of multiplexing outbound messages and requests received from a plurality of AAA servers. The AAA protocol supported by the invention includes, but is not limited to, a Diameter protocol, a lightweight directory access protocol (LDAP), and the likes.
    Type: Application
    Filed: April 17, 2008
    Publication date: October 22, 2009
    Applicant: RADWARE, LTD.
    Inventor: Amir Peles
  • Patent number: 7607170
    Abstract: A method for detecting an attack in a computer network includes monitoring communication traffic transmitted over connections on the network that are associated with a stateful application protocol so as to detect respective states of the connections, and analyzing a distribution of the states so as to detect the attack.
    Type: Grant
    Filed: December 22, 2004
    Date of Patent: October 20, 2009
    Assignee: Radware Ltd.
    Inventor: Avi Chesla
  • Publication number: 20090132714
    Abstract: A system, method and device for providing connection resiliency. The method including maintaining, by a first proxy, a TCP connection with a TCP client and a TCP connection with a TCP server through one or more TCP networks; maintaining information of both TCP connections by a forwarding component between the TCP networks and the first proxy; establishing, by the forwarding component, a new TCP connection with a second proxy for each of the TCP connections maintained by the first proxy; and forwarding data, to and from both the client and the server, to and from the second proxy without disconnection of the TCP connections of the TCP client and TCP server.
    Type: Application
    Filed: November 20, 2007
    Publication date: May 21, 2009
    Applicant: RADWARE, LTD.
    Inventors: Emanuel Blander, Amir Peles
  • Publication number: 20090043724
    Abstract: A method for preventing session initiation protocol (SIP) attacks is provided. The method includes receiving a plurality of SIP response messages comprising at least one pre-defined SIP response code, and extracting at least one user identifier from the plurality of SIP response messages. The method further includes computing at least one of a frequency of the plurality of SIP response messages and a count of the plurality of SIP response messages corresponding to each user identifier of the at least one user identifier. The method further includes calculating a degree of attack corresponding to each user identifier using at least one of the frequency and the count. The method further includes determining a monitoring interval for each user identifier based upon the degree of attack for monitoring the plurality of SIP response messages. An apparatus and a computer program product for preventing SIP attacks are also provided.
    Type: Application
    Filed: August 8, 2007
    Publication date: February 12, 2009
    Applicant: RADWARE, LTD.
    Inventor: Avi Chesla
  • Publication number: 20080282254
    Abstract: A mechanism for achieving resiliency and load balancing for SIP application services and, in particular, in geographic distributed sites. A method performs a distribution of SIP requests among SIP servers, where at least two sites with a load balancer in each site is configured. The method includes receiving a SIP request by a first load balancer in a first site; determining whether the SIP request should be redirected to a second site; and redirecting the SIP request to an address of a second load balancer in the second site. The invention also includes a SIP proxy including a receiving unit receiving SIP requests; a load balancing unit distributing SIP requests between SIP entities; and a health monitoring unit verifying availability of the SIP entities. The SIP proxy may further be configured with a proximity measuring unit determining a proximity to a SIP entity.
    Type: Application
    Filed: May 9, 2007
    Publication date: November 13, 2008
    Applicant: RADWARE, LTD.
    Inventors: Emanuel Blander, Amir Peles
  • Publication number: 20080086435
    Abstract: A system and method to detect and mitigate denial of service and distributed denial of service HTTP “page” flood attacks. Detection of attack/anomaly is made according to multiple traffic parameters including rate-based and rate-invariant parameters in both traffic directions. Prevention is done according to HTTP traffic parameters that are analyzed once a traffic anomaly is detected. This protection includes a differential adaptive mechanism that tunes the sensitivity of the anomaly detection engine. The decision engine is based on a combination between fuzzy logic inference systems and statistical thresholds. A “trap buffer” characterizes the attack to allow an accurate mitigation according to the source IP(s) and the HTTP request URL's that are used as part of the attack. Mitigation is controlled through a feedback mechanism that tunes the level of rate limit factors that are needed in order to mitigate the attack effectively while letting legitimate traffic to pass.
    Type: Application
    Filed: October 9, 2007
    Publication date: April 10, 2008
    Applicant: Radware, Ltd.
    Inventor: Avi Chesla
  • Publication number: 20080086434
    Abstract: A system and method to detect and mitigate denial of service and distributed denial of service HTTP “page” flood attacks. Detection of attack/anomaly is made according to multiple traffic parameters including rate-based and rate-invariant parameters in both traffic directions. Prevention is done according to HTTP traffic parameters that are analyzed once a traffic anomaly is detected. This protection includes a differential adaptive mechanism that tunes the sensitivity of the anomaly detection engine. The decision engine is based on a combination between fuzzy logic inference systems and statistical thresholds. A “trap buffer” characterizes the attack to allow an accurate mitigation according to the source IP(s) and the HTTP request URL's that are used as part of the attack. Mitigation is controlled through a feedback mechanism that tunes the level of rate limit factors that are needed in order to mitigate the attack effectively while letting legitimate traffic to pass.
    Type: Application
    Filed: October 9, 2007
    Publication date: April 10, 2008
    Applicant: RADWARE, LTD.
    Inventor: Avi Chesla
  • Publication number: 20080086772
    Abstract: A distributed security system wherein intelligent security agents (i.e., agent devices) share security incident information between themselves via a controller. An adaptive security decision making involving network worms (non-SMTP worms) and DoS floods attacks is also described; wherein the Worms and DoS flood digital signatures are generated to assist in intrusion prevention process.
    Type: Application
    Filed: October 9, 2007
    Publication date: April 10, 2008
    Applicant: RADWARE, LTD.
    Inventor: Avi Chesla
  • Publication number: 20080052774
    Abstract: A method for protecting a network from an attack includes measuring a property of traffic entering the network, and analyzing the property using at least one fuzzy logic algorithm in order to detect the attack.
    Type: Application
    Filed: October 24, 2007
    Publication date: February 28, 2008
    Applicant: RADWARE LTD.
    Inventors: Avi Chesla, Lev Medvedovsky, Abraham Elboim