Patents Assigned to TUFIN SOFTWARE TECHNOLOGIES LTD.
  • Patent number: 9578030
    Abstract: There are provided a rule-set analyzer and a method of analyzing an ordered security rule-set comprising a plurality of rules and characterized by at least one extrinsic field. The method comprises: upon specifying atomic elements constituting an extrinsic space corresponding to the at least one extrinsic field, partitioning, by a processor, the extrinsic space into two or more equivalence classes, wherein each atomic element in the extrinsic space belongs to one and only one equivalence class; mapping, by the processor, said equivalence classes over the rule-set; and analyzing, by the processor, the security rule-set using the results of mapping said equivalence classes over the rule-set.
    Type: Grant
    Filed: July 10, 2014
    Date of Patent: February 21, 2017
    Assignee: TUFIN SOFTWARE TECHNOLOGIES LTD.
    Inventor: Yoni Lavi
  • Patent number: 9203808
    Abstract: There are provided a method of automated managing an ordered set of security rules implemented at a plurality of security gateways and a system thereof. The method comprises obtaining data characterizing a connectivity request which may become allowable only upon changes of an initial rule-set, thus giving rise to an unfitting connectivity request; analyzing routing tables of the plurality of the security gateways; generating ranking the security gateways in accordance with their relevance to the unfitting connectivity request; selecting one or more security gateways with the highest ranking; and implementing a configuration change required in order to facilitate allowance of the unfitting connectivity request at the one or more selected security gateways.
    Type: Grant
    Filed: May 1, 2013
    Date of Patent: December 1, 2015
    Assignee: TUFIN SOFTWARE TECHNOLOGIES LTD.
    Inventors: Reuven Harrison, Michael Hamelin
  • Patent number: 9122990
    Abstract: There are provided a method of automated managing one or more security rule-sets and a system thereof. The method comprising: obtaining data characterizing a connectivity request and an amended rule-set, the amended rule-set being derivative of an initial rule-set amended to fit the connectivity request; automated verifying each possible combination of values in the connectivity request against the initial rule-set and the amended rule-set; calculating one or more values selected from a group comprising values characterizing relative amount of extra allowed traffic and values characterizing relative amount of dissatisfied requested traffic; automated comparing the calculated values and/or derivatives thereof with a predefined threshold; and automated classifying the amended rule-set as applicable for implementation if the results of the automated comparing match a predefined verification criterion.
    Type: Grant
    Filed: May 21, 2013
    Date of Patent: September 1, 2015
    Assignee: TUFIN SOFTWARE TECHNOLOGIES LTD.
    Inventors: Reuven Harrison, Amir Cogan, Tomer Barkan
  • Publication number: 20130254150
    Abstract: There are provided a method of automated managing one or more security rule-sets and a system thereof. The method comprising: obtaining data characterizing a connectivity request and an amended rule-set, the amended rule-set being derivative of an initial rule-set amended to fit the connectivity request; automated verifying each possible combination of values in the connectivity request against the initial rule-set and the amended rule-set; calculating one or more values selected from a group comprising values characterizing relative amount of extra allowed traffic and values characterizing relative amount of dissatisfied requested traffic; automated comparing the calculated values and/or derivatives thereof with a predefined threshold; and automated classifying the amended rule-set as applicable for implementation if the results of the automated comparing match a predefined verification criterion.
    Type: Application
    Filed: May 21, 2013
    Publication date: September 26, 2013
    Applicant: TUFIN SOFTWARE TECHNOLOGIES LTD.
    Inventors: Reuven HARRISON, Amir COGAN, Tomer BARKAN
  • Publication number: 20130247169
    Abstract: There are provided a method of automated managing an ordered set of security rules implemented at a plurality of security gateways and a system thereof. The method comprises obtaining data characterizing a connectivity request which may become allowable only upon changes of an initial rule-set, thus giving rise to an unfitting connectivity request; analyzing routing tables of the plurality of the security gateways; generating ranking the security gateways in accordance with their relevance to the unfitting connectivity request; selecting one or more security gateways with the highest ranking; and implementing a configuration change required in order to facilitate allowance of the unfitting connectivity request at the one or more selected security gateways.
    Type: Application
    Filed: May 1, 2013
    Publication date: September 19, 2013
    Applicant: TUFIN SOFTWARE TECHNOLOGIES LTD.
    Inventors: Reuven HARRISON, Michael HAMELIN
  • Publication number: 20110060713
    Abstract: There are provided a method of automated managing two or more security rule-sets and a system thereof. The method comprises: obtaining data characterizing a first rule-set and a second rule-set; automated recognizing all possible combinations of values in the first and the second rule-sets; automated verifying each combination of values in the second rule-set against the first rule-set; calculating one or more values characterizing the differences in allowable and rejectable traffic in the first rule-set and the second rule-set; automated comparing the calculated values and/or derivatives thereof with a predefined threshold; and automated classifying the relationship between the first rule-set and the second rule-set in accordance with comparison results.
    Type: Application
    Filed: September 20, 2010
    Publication date: March 10, 2011
    Applicant: TUFIN SOFTWARE TECHNOLOGIES LTD.
    Inventors: Reuven Harrison, Amir Cogan, Tomer Barkan
  • Publication number: 20100299741
    Abstract: There are provided a method of automated managing an ordered set of security rules implemented at one or more security gateways and a system thereof. The method comprises a) obtaining data characterizing a connectivity request which may become allowable only upon changes of an initial rule-set, thus giving rise to an unfitting connectivity request; b) automated searching for a rule within said ordered set of security rules, said rule best matching to be amended in order to facilitate allowance of the unfitting connectivity request, wherein best matching is defined in accordance with one or more predefined criteria; c) automated generating amendment of the best matching rule, said amendment capable to facilitate allowance of the unfitting connectivity request; and d) automated implementing the generated amendment at one or more relevant security gateways among said one or more security gateways.
    Type: Application
    Filed: May 17, 2010
    Publication date: November 25, 2010
    Applicant: TUFIN SOFTWARE TECHNOLOGIES LTD.
    Inventors: Reuven Harrison, Michael Hamelin
  • Publication number: 20100011433
    Abstract: There is provided a rule-set generator and a method of automated configuration of a security gateway. The method comprises setting-up an initial rule-set; obtaining log records of communication events corresponding to the initial rule-set so as to obtain a sufficient amount of log records; transforming the obtained log records into respective rules, wherein source, destination and service fields in each rule correspond to source, destination and service values in respective obtained log record, and the action in all rules is defined as “Accept”, thus giving rise to a transformation-based rule-set; and processing the transformation-based rule-set so as to generate an operable rule-set by processing the transformation-based rule-set.
    Type: Application
    Filed: July 14, 2008
    Publication date: January 14, 2010
    Applicant: TUFIN SOFTWARE TECHNOLOGIES LTD.
    Inventors: Reuven HARRISON, Yakov PERSKY
  • Publication number: 20090138938
    Abstract: Provided a computerized system and method of automated auditing a range of rules associated with an enforced security policy. The method comprises automated obtaining log records assigned to a first rule within the range of rules and logged during a counted period, each said log record comprising a unique rule identifier and recorded values of respective arguments comprised in the rule; counting a number of records matching certain recorded values and logged within certain time intervals within the counted period (counted values); and automated generating a counted log record assigned to said rule, said record comprising the unique rule identifier, the counted period, recorded values of the rule arguments and respective counted values.
    Type: Application
    Filed: December 6, 2007
    Publication date: May 28, 2009
    Applicant: TUFIN SOFTWARE TECHNOLOGIES LTD.
    Inventors: Reuven Harrison, Reuven Kitov