Patents Assigned to Radware Ltd.
  • Patent number: 10616356
    Abstract: A system and method for optimization of resource pushing are presented. The method includes intercepting a current request for web content from a client device; determining a current PUSH list from at least one generated PUSH list based on the current request, wherein each generated PUSH list ensures availability of resources to the client device prior to receiving of a response, from an origin server, corresponding to the request; and pushing, in real-time, resources to the client device based on the determined PUSH list. Some embodiments also include a method and system for generating PUSH lists for optimizing asynchronous resource pushing.
    Type: Grant
    Filed: February 24, 2016
    Date of Patent: April 7, 2020
    Assignee: Radware, Ltd.
    Inventors: Kent Douglas Alstad, Shawn David Bissell, Jarrod Patrick Thomas Connolly
  • Patent number: 10601845
    Abstract: A method for a predictive detection of cyber-attacks are provided. In an embodiment, the method includes receiving security events; matching each received security event to a plurality of previously generated event sequences to result in at least one matched event sequence; comparing each of the at least one matched event sequence to a plurality of previously identified attack patterns to result in at least one matched attack pattern; for each matched attack pattern, computing a risk score potentially indicating a cyber-attack; and causing execution of a mitigation action based on the risk score.
    Type: Grant
    Filed: August 31, 2017
    Date of Patent: March 24, 2020
    Assignee: RADWARE, LTD.
    Inventors: Yotam Ben Ezra, Mor Krispil
  • Patent number: 10523693
    Abstract: A system and method for real-time tuning of inference systems based on quality of incoming data. The method comprises: periodically receiving traffic data collected by a plurality of collectors deployed in a network; determining at least a normalized variance of a current sample of the received traffic data; estimating, based in part on the normalized variance, a standard deviation of the received traffic data and a fading coefficient of a baseline filter; determining a current baseline value based on a previous baseline value, the fading coefficient, and the current sample of the traffic data; and dynamically setting at least one membership function of the inference system based in part on the current baseline value and the standard deviation.
    Type: Grant
    Filed: April 10, 2017
    Date of Patent: December 31, 2019
    Assignee: Radware, Ltd.
    Inventors: Lev Medvedovsky, David Aviv, Ehud Doron, Asaf Oron, Yuriy Arbitman
  • Publication number: 20190334904
    Abstract: A method and system for determining a cost to allow a blockchain-based admission to a protected entity. The method includes identifying, in a blockchain network, a conversion transaction identifying a conversion of a first-type of access tokens with access tokens of a second-type, wherein the transaction designates at least the protected entity; determining a conversion value for converting the first-type of access tokens into the second-type access tokens, wherein the conversion value is determined based on at least one access parameter; and converting, based on the determined conversion value, a first sum of the first-type access tokens into a second sum of the second-type access-tokens, wherein a client spends the second sum of the second-type access tokens to access the protected entity, the determined conversion value is the access cost to the protected entity.
    Type: Application
    Filed: May 31, 2018
    Publication date: October 31, 2019
    Applicant: RADWARE, LTD.
    Inventors: Alon LELCUK, David AVIV
  • Publication number: 20190334886
    Abstract: A system and method for blockchain-based access authorization to a protected entity. The method includes: receiving, by the protected entity, an access request to a protected entity, wherein the access request is received from a client device; extracting a unique client identifier from the received access request; causing the client device to perform an admission process; monitoring a blockchain network to identify at least one admission transaction, wherein the at least one admission transaction designates admission criteria; determining if the admission criteria satisfy a set of conditions for accessing the protected entity; and granting access to the client device when the admission criteria satisfies the set of conditions, wherein the access is access to the protected entity.
    Type: Application
    Filed: April 15, 2019
    Publication date: October 31, 2019
    Applicant: RADWARE, LTD.
    Inventors: Alon LELCUK, David AVIV
  • Publication number: 20190334717
    Abstract: A method and system for blockchain-based access to a protected entity are provided. The method includes granting access tokens of a first-type to a client; identifying, in a blockchain network, a conversion transaction identifying a request to convert the first-type of access tokens with access tokens of a second-type, wherein the transaction designates at least the protected entity; determining a conversion value for converting the first-type of access tokens into the second-type of access tokens, wherein the conversion value is determined based on at least one access parameter; converting, based on the determined conversion value, a first sum of the first-type of access tokens into a second sum of the second-type of access-tokens; and granting the client access to the protected entity when the sum of the second-type of access tokens is received as a payment from the protected entity.
    Type: Application
    Filed: May 31, 2018
    Publication date: October 31, 2019
    Applicant: RADWARE, LTD.
    Inventors: Alon LELCUK, David AVIV
  • Publication number: 20190334905
    Abstract: A method and a trust broker system for blockchain-based anti-bot protection are provided. The method includes identifying, on a blockchain network, a request from a client to access a protected entity; selecting an access policy in response to the access request, wherein the access policy includes at least one game to be performed by the client; causing execution of the at least one game defined in the access policy; identifying, on the blockchain network, results of the at least one game, wherein the results are deposited by the client upon completion of the game; determining a bias of the client based on the completion results, wherein the determined bias is utilized for a cyber-security assessment of the client, wherein the determined bias for the client is maintained on the blockchain network; and granting or denying access to the protected entity by the client based on the determined bias.
    Type: Application
    Filed: November 6, 2018
    Publication date: October 31, 2019
    Applicant: RADWARE, LTD.
    Inventors: Alon LELCUK, David AVIV
  • Publication number: 20190306188
    Abstract: A method and system for detecting and mitigation recursive domain name system (DNS) cyber-attacks are disclosed. The method includes receiving DNS queries directed to a DNS resolver, wherein the DNS resolver is communicatively connected between at least one client and at least one name server; parsing each received DNS query to extract a hostname identified therein; updating at least one array of Bloom filters using the extracted hostname; computing a ratio of an unrecognized hostnames per sample (UPS) based on the contents of the at least one array; and determining if the UPS ratio is abnormal, wherein an abnormal UPS ratio is an indication of an attack.
    Type: Application
    Filed: March 29, 2018
    Publication date: October 3, 2019
    Applicant: RADWARE, LTD.
    Inventors: Lev MEDVEDOVSKY, David AVIV
  • Patent number: 10397246
    Abstract: A crowdsourcing log analysis system and methods for protecting computers and networks from malware attacks by analyzing data log information obtained from a plurality of client network. The client networks are associated with a set of network entities representing a plurality of business units or customers. The system may further comprise a plurality of server machines, each operable to execute a security product associated with a security product vendor and log associated information of at the network entities into at least one log file. The log files may be uploaded onto a breach detection platform for analysis based upon crowdsourcing principles and is operable to generate a risk factor attribute for at least one suspect entity.
    Type: Grant
    Filed: June 15, 2015
    Date of Patent: August 27, 2019
    Assignee: Radware, Ltd.
    Inventors: Aviv Raff, Doron Peri, Amnon Lotem
  • Patent number: 10375158
    Abstract: A system and method for managing an application delivery controller (ADC) cluster including a plurality of ADCs are provided. The method includes creating a hash table including a plurality of buckets, wherein a number of the plurality of buckets is a multiple of a maximum number of active ADCs that can be supported by the ADC cluster; allocating, to each active ADC of the ADC cluster, one of the plurality of buckets; and instructing at least one network element to distribute traffic to and from the active ADCs based on the hash table.
    Type: Grant
    Filed: July 1, 2016
    Date of Patent: August 6, 2019
    Assignee: RADWARE, LTD.
    Inventors: Benny Rochwerger, Ehud Doron, Kobi Samoray
  • Patent number: 10374918
    Abstract: A method and system for configuring a behavioral network intelligence system using a network monitoring programming language are provided. The method includes defining at least one target of a traffic segment to be monitored using at least one application path attribute of an application, wherein the application is accessed via at least one user device connected to a network, wherein the at least one application path attribute is defined respective of an application path keyword and an application path assessment keyword; and defining at least one condition representing the behavior of the at least one application path attribute of the application, the at least one target and the at least one condition can be interpreted by a monitoring system to allow for determining a behavioral impact of the application on the network.
    Type: Grant
    Filed: December 4, 2014
    Date of Patent: August 6, 2019
    Assignee: Radware, Ltd.
    Inventors: Lev Medvedovsky, David Aviv, Avi Chesla
  • Patent number: 10355949
    Abstract: A method and system for determining the behavioral impact of applications and their respective users on a network carrier are provided. The method includes receiving data collected by at least one deep packet inspection (DPI) engine; classifying the received data at least per an application path respective of each of the applications; generating an application path profile data structure using the collected data; and generating, responsive to at least one behavioral rule, at least one degree of fulfillment (DoF) for the application path based on contents of the application path profile data structure, wherein the at least DoF defines an association of the application path with at least one behavior group, wherein the behavior group determines the behavioral impact of an application represented by the application path.
    Type: Grant
    Filed: December 4, 2014
    Date of Patent: July 16, 2019
    Assignee: RADWARE, LTD.
    Inventors: Avi Chesla, David Aviv, Lev Medvedovsky
  • Publication number: 20190199746
    Abstract: A system and method for reducing a time to mitigate distributed denial of service (DDoS) attacks are provided. The method includes receiving a plurality of attack feeds on at least one protected object in a secured environment; analyzing the plurality of attack feeds to determine characteristics of a DDoS attack against the secure environment; determining a set of optimal mitigation resources assigned to the secured environment; selecting, based on the set of optimal mitigation resources and the attack characteristics, at least one optimal workflow scheme; and initiating a proactive mitigation action by setting each mitigation resource in the set of optimal mitigation resources according to the selected optimal workflow scheme.
    Type: Application
    Filed: December 20, 2018
    Publication date: June 27, 2019
    Applicant: RADWARE, LTD.
    Inventors: Ehud DORON, Yotam BEN EZRA, David AVIV
  • Publication number: 20190182291
    Abstract: A system and method for generating insights on distributed denial of service (DDoS) attacks are provided. The method includes receiving a plurality of data feeds from a plurality of data sources; processing the plurality of received data feeds to generate enriched data sets; and analyzing the enriched data sets to generate insights information about a DDoS attack that have been participated in at least one DDoS attack.
    Type: Application
    Filed: December 11, 2018
    Publication date: June 13, 2019
    Applicant: RADWARE, LTD.
    Inventors: Ehud DORON, Yotam BEN EZRA, David AVIV
  • Publication number: 20190182266
    Abstract: A system and method for out-of-path detection of cyber-attacks are provided. The method includes receiving, by a detector, a plurality of data feeds from a plurality of data sources, wherein the detector is communicatively connected to the plurality of data sources; processing, by the detector, the plurality of received data feeds to generate enriched Flow data sets; analyzing the enriched Flow data sets to detect a potential cyber-attack; and upon detection of a potential cyber-attack, providing indication to each network entity of the network entities that is under attack.
    Type: Application
    Filed: December 6, 2018
    Publication date: June 13, 2019
    Applicant: RADWARE, LTD.
    Inventors: Ehud DORON, Yotam BEN EZRA, David AVIV
  • Publication number: 20190182274
    Abstract: A method and system for predicting subsequent cyber-attacks in attack campaigns are provided. The method includes receiving events data related to cyber-attacks occurring in a network during a predefined time window; extracting at least one sequence from the received events data at least one attack vector; generating a sequence signature for each of the at least one extracted sequence; comparing each sequence signature to a representation of historic sequence signatures to determine at least partially matching sequence signature; and based on the matching sequence, determining at least one subsequent cyber-attack in a respective sequence.
    Type: Application
    Filed: December 11, 2018
    Publication date: June 13, 2019
    Applicant: RADWARE, LTD.
    Inventors: Ehud DORON, Amnon LOTEM, Yotam BEN-EZRA, Ami NAVON, Nadav GROSSAUG, Nissim PARIENTE
  • Publication number: 20190116103
    Abstract: A system and method for identifying botnets. The method includes determining a network event proximity based on collected network data, where the network data relates to at least one network device; determining time density of the network data; determining trend patterns of the network data; and determining, based on the network event proximity, time density, and trend patterns, when a botnet activity is present within the network data.
    Type: Application
    Filed: October 15, 2018
    Publication date: April 18, 2019
    Applicant: RADWARE, LTD.
    Inventors: Zeev RAVID, Mor KRISPIL
  • Publication number: 20190052671
    Abstract: A method and system for controlling multi-tiered mitigation of cyber-attacks.
    Type: Application
    Filed: October 18, 2018
    Publication date: February 14, 2019
    Applicant: RADWARE, LTD.
    Inventors: Ehud DORON, David AVIV, Yotam BEN EZRA, Lev MEDVEDOVSKY
  • Patent number: 10200382
    Abstract: A system and method for detecting abnormal traffic behavior. The method comprises: applying a task to an input data set to create an un-normalized cluster of traffic features, wherein the task defines a plurality of traffic features; computing a center point of the cluster of traffic features; computing a distance between the computed center point and a new sample, wherein the new sample includes traffic features defined in the task; and determining, based on the computed distance, whether the received new sample demonstrates abnormal behavior.
    Type: Grant
    Filed: November 5, 2015
    Date of Patent: February 5, 2019
    Assignee: RADWARE, LTD.
    Inventors: Lev Medvedovsky, David Aviv
  • Patent number: 10157236
    Abstract: In a client/server environment, rendering of web-based content is separated into two phases, so as to improve the applicability of HTML response caching. Static portion(s) of a web page are cached and delivered immediately in response to an HTTP request, concurrently with sending a request for a full page and extracting dynamic portion(s) therefrom. Dynamic portion(s) are filled in at the client as they become available. The system and method of the present invention enable optimization of the user experience to occur without requiring any recoding of the original page content.
    Type: Grant
    Filed: May 18, 2012
    Date of Patent: December 18, 2018
    Assignee: Radware, Ltd.
    Inventor: Kent Alstad