Patents Assigned to Varonis Systems, Inc.
-
Patent number: 12197483Abstract: Device, system, and method for automatically detecting and classifying personally identifiable information (PII) in documents and files. A method includes performing a deterministic rule-based search, in a plurality of stored documents, for PII data-items. If the deterministic rule-based search indicates that a particular document is more likely than not to contain a PII data-items then the method includes: extracting a textual snippet from the particular document, wherein the textual snippets surrounds the PII data-item; adding the textual snippet and the particular document to one or more training datasets utilized for training a Large Language Model (LLM) configured to find PII data-items in documents for Named Entity Recognition (NER) in those documents.Type: GrantFiled: November 1, 2023Date of Patent: January 14, 2025Assignee: VARONIS SYSTEMS, INC.Inventors: Peter Shmukler, Amit Cohen, Lior Chen, Nir Zinger
-
Publication number: 20240414167Abstract: A system and method for dynamically refining access rules for governing control of access by multiple users to data elements or services (DEOSs) stored in or accessed through at least one access controllable network element (ACONE), including collecting initial permissions to the DEOSs, receiving and periodically updating notifications of actual access events of the multiple users to the DEOSs, generating initial user groups for the multiple users, generating for each of the initial user groups, based at least partially on the notifications of actual access events, a list of users who have accessed at least one of the DEOSs, based at least partially on the lists, generating modified user groups, based at least partially on the modified user groups, generating modified permissions, and based on the modified permissions, updating the initial permissions to the DEOSs, thereby enabling only the users in particular modified user groups to access particular DEOSs.Type: ApplicationFiled: June 12, 2023Publication date: December 12, 2024Applicant: VARONIS SYSTEMS, INC.Inventors: John (Eugene) NEYSTADT, Lior CHEN
-
Publication number: 20240378127Abstract: A system for monitoring data elements, including a data element monitor (DEM), monitoring a multiplicity of data elements, some of which having associated therewith a data representation, each of the multiplicity of data elements including data element content and data element information, and each of the data representations including data representation information corresponding to at least a subset of the data element information, an event notification ascertainer (ENA), ascertaining which of the multiplicity of the data elements being monitored has an event notification associated therewith and a difference reporter, reporting a difference between the data representation information in a data representation associated with one of the multiplicity of data elements being monitored, which has an event notification associated therewith, and corresponding data element information of that one of the multiplicity of the data elements being monitored which has an event notification associated therewith.Type: ApplicationFiled: December 15, 2022Publication date: November 14, 2024Applicant: VARONIS SYSTEMS, INC.Inventors: David BASS, Yakov FAITELSON, Ophir KRETZER-KATZIR, Orr KADEC
-
Publication number: 20240193290Abstract: A method for automatic management of user permissions in an organization including automatically grouping users into a plurality of user clusters based on at least one similarity between users in each user cluster, for each user cluster, automatically generating a set of cluster user permissions, the set of cluster user permissions including user permissions belonging to users in the cluster and actively used by at least one user in the cluster and for each user cluster, automatically modifying user permissions of each user in each cluster in accordance with the set of cluster user permissions.Type: ApplicationFiled: December 9, 2022Publication date: June 13, 2024Applicant: VARONIS SYSTEMS, INC.Inventors: Igor Grossman, John Eugene Neystadt, Evgeny Gilgurt, Lior Chen, David Bass
-
Publication number: 20240111858Abstract: A system for automatically monitoring efficacy of security controls in a computer network, including a probe engine configurable with at least one set of rules relating to access permissions to data in the computer network, at least one security probe forming part of the probe engine and operative to automatically place, at at least one storage location within the computer network and with access permissions that are non-compliant with the at least one set of rules, simulated data corresponding to the data in the computer network and attempt to access the simulated data following the placement thereof, using access privileges satisfying the non-compliant access permissions, and a security monitoring and reporting module operative to provide a user sensible output indicating at least whether the attempt to access the simulated data was successful and, if so, reporting mitigating activities by the security controls in response to the successful attempt.Type: ApplicationFiled: October 3, 2022Publication date: April 4, 2024Applicant: VARONIS SYSTEMS, INC.Inventors: John NEYSTADT, Shay AZULAY, Amit COHEN, Lior CHEN
-
Patent number: 11586600Abstract: A method for in-advance obtaining properties of objects of a computerized system, the method comprising receiving a request for properties of a first object, and responsively providing the requested properties along with properties of an at least one another object that are similar to the properties of the first object, wherein the properties of the at least one another object are similar to the properties of the first object by having at least one element of properties that are common therebetween, and wherein the method is carried out by an at least one apparatus component of the computerized system, and an apparatus for performing the same.Type: GrantFiled: November 5, 2013Date of Patent: February 21, 2023Assignee: VARONIS SYSTEMS, INCInventors: Yakov Faitelson, Ohad Korkus, Ophir Kretzer-Katzir
-
Patent number: 11487805Abstract: A method for indexing objects in a computerized system having an index, comprising identifying in the computerized system an at least one indexed object that meets an at least one criterion related to contents of the at least one indexed object, detecting an at least one non-indexed object having a property similar to an at least one property of the at least one indexed object that was identified, and indexing the at least one non-indexed object in the index, wherein the method is performed by the computerized system, and an apparatus for performing the same.Type: GrantFiled: October 19, 2020Date of Patent: November 1, 2022Assignee: VARONIS SYSTEMS, INC.Inventors: Yakov Faitelson, Ohad Korkus, Ophir Kretzer-Katzir
-
Patent number: 11386224Abstract: A method for managing personal digital identifiers of a user in data elements stored in a computerized system may include receiving personal digital identifiers for identifying a user. The data elements may be searched for the personal digital identifiers and data elements may be identified as having the personal digital identifiers of the user. One or more candidate personal digital identifiers in the identified data elements may be assigned as one or more common words appearing in the identified data elements when a word count for each of the one or more common words exceeds a predefined threshold. The user may validate the candidate personal digital identifiers, which may be added to the personal digital identifiers of the user. A personal digital footprint of the user including a location in the computerized system for each of the personal digital identifiers in the identified data elements may be stored.Type: GrantFiled: March 20, 2019Date of Patent: July 12, 2022Assignee: VARONIS SYSTEMS INCInventors: Yakov Faitelson, Ophir Kretzer-Katzir, David Bass
-
Patent number: 11388004Abstract: A system for preventing an excess user authentication token utilization condition in an enterprise computer environment, the system including an excess user authentication token utilization condition predictor operable for calculating a number of additional group memberships of each of the enterprise users that can be expected to result in an excess user authentication token utilization condition, a group membership estimator operable, for each the enterprise user, for estimating a number of additional group memberships of the enterprise user that will be created by an anticipated activity, and an anticipated excess user authentication token utilization condition alerter operable, before initiation of the anticipated activity, for providing an alert if the anticipated activity can be expected to result in an excess user authentication token utilization condition.Type: GrantFiled: October 3, 2018Date of Patent: July 12, 2022Assignee: VARONIS SYSTEMS, INC.Inventors: Yakov Faitelson, Ophir Kretzer-Katzir
-
Patent number: 11138153Abstract: A method for characterizing data elements in an enterprise including ascertaining at least one of an access metric and a data identifier for each of a plurality of data elements and employing the at least one of an access metric and a data identifier to automatically apply a metatag to ones of the plurality of data elements.Type: GrantFiled: April 15, 2019Date of Patent: October 5, 2021Assignee: VARONIS SYSTEMS, INC.Inventors: Yakov Faitelson, Ohad Korkus, Ophir Kretzer-Katzir, David Bass
-
Patent number: 11042550Abstract: A method for managing data in an enterprise by identifying data of interest from among a multiplicity of data elements in an enterprise, the method including characterizing data of interest at least by at least one non-content based data identifier thereof and at least one access metric thereof, the at least one access metric being selected from data access permissions and actual data access history and selecting data of interest by considering only data elements from among the multiplicity of data elements which have the at least one non-content based data identifier thereof and the at least one access metric thereof.Type: GrantFiled: July 3, 2018Date of Patent: June 22, 2021Assignee: VARONIS SYSTEMS, INC.Inventors: Yakov Faitelson, Ohad Korkus, Ophir Kretzer-Katzir, David Bass
-
Patent number: 10855631Abstract: A computerized method for managing a collaboration of objects via stubs may include a computerized apparatus linked to a computerized system and configured to intercept an outgoing communication including an object, to identify an instance of the object in a storage of the computerized system, to generate a stub of the instance of the object specifying a location of the identified instance the object in the storage of the computerized device, to replace the object in the outgoing communication with the stub, and to send the outgoing communication including the stub to a recipient.Type: GrantFiled: March 27, 2019Date of Patent: December 1, 2020Assignee: VARONIS SYSTEMS INC.Inventors: Yakov Faitelson, Ophir Kretzer-Katzir, David Bass
-
Publication number: 20200336485Abstract: A system for providing bi-directional visualization of authority of users over SACs in an enterprise-wide network, the system including functionality for providing user-wise visualization of the authority of a given user over at least one SAC in respect of which the user has authority, and functionality for providing SAC-wise visualization for a given SAC of the authority of at least one user over the given SAC.Type: ApplicationFiled: June 29, 2020Publication date: October 22, 2020Applicant: Varonis Systems, Inc.Inventors: Yakov FAITELSON, Ohad KORKUS, Ophir KRETZER-KATZIR
-
Patent number: 10721234Abstract: A system for providing bi-directional visualization of authority of users over SACs in an enterprise-wide network, the system including functionality for providing user-wise visualization of the authority of a given user over at least one SAC in respect of which the user has authority, and functionality for providing SAC-wise visualization for a given SAC of the authority of at least one user over the given SAC.Type: GrantFiled: November 24, 2011Date of Patent: July 21, 2020Assignee: VARONIS SYSTEMS, INC.Inventors: Yakov Faitelson, Ohad Korkus, Ophir Kretzer-Katzir
-
Patent number: 10642791Abstract: A computerized method and apparatus for distinguishing between false positive read events and true positive events of reading a file, comprising determining an amount of date read from the file, in case the amount of data exceeds a threshold generating a true positive read event, otherwise generating a false positive read event in case a decision condition is met, and an apparatus to carry out the same.Type: GrantFiled: March 26, 2017Date of Patent: May 5, 2020Assignee: VARONIS SYSTEMS, INC.Inventors: Yakov Faitelson, Ohad Korkus, David Bass, Yzhar Kaysar, Doron Goldstein, Oren David
-
Patent number: 10476878Abstract: An access permissions management system including a hierarchical access permissions repository including access permissions relating to data elements arranged in a data element hierarchy, wherein some of the data elements have only access permissions which are inherited from ancestral data elements, some of the multiplicity of data elements are prevented from having inherited access permissions and thus have only unique access permissions which are not inherited and some of the data elements are not prevented from having inherited access permissions and have not only inherited access permissions but also unique access permissions which are not inherited, some of which unique access permissions possibly being redundant with inherited access permissions, and an access permissions redundancy prevention engine operative to ascertain which of the unique access permissions are redundant with inherited access permissions and not to store the unique access permissions which are redundant with inherited access permissType: GrantFiled: September 7, 2018Date of Patent: November 12, 2019Assignee: Varonis Systems, Inc.Inventors: Yakov Faitelson, Ohad Korkus, Ophir Kretzer-Katzir, Yzhar Keysar
-
Patent number: 10346361Abstract: A method of controlling file access events in a computerized server, including receiving by a computer acting as a server and connected to a network of computer platforms, information of file access events intercepted by the computer platforms, accessing rules for processing file access events, retrieving auxiliary data disjoint of the event, and processing the event by the server based on the rule and the auxiliary data to determine an action for handling the event for the computer platform.Type: GrantFiled: November 2, 2016Date of Patent: July 9, 2019Assignee: VARONIS SYSTEMS, INC.Inventors: Yakov Faitelson, Ohad Korkus, Ophir Kretzer-Katzir
-
Patent number: 10320798Abstract: A method for controlling access to a file system having data elements, including the steps of maintaining a record of respective actual accesses by users of the file system to the data elements, defining a proposed removal of a set of the users from a superset of the users, wherein members of the superset have common access privileges to a portion of the data elements, and wherein following an implementation of the proposed removal, members of the set retain respective proposed residual access permissions, ascertaining, prior to the implementation of the proposed removal, that at least one of the respective actual accesses are disallowed to the members of the set, or to non-members of the set having actual access profiles which are similar to the actual access profiles of the members of the set, by the respective proposed residual access permissions, and generating an error indication, responsively to the ascertaining.Type: GrantFiled: February 1, 2016Date of Patent: June 11, 2019Assignee: VARONIS SYSTEMS, INC.Inventors: Yakov Faitelson, Ohad Korkus
-
Patent number: 10318751Abstract: A system for automatically replacing a user security group-based computer security policy by a computer security policy based at least partially on actual access, including a learned access permissions subsystem operative to learn current access permissions of users to network objects in an enterprise computer environment and to provide an indication of which users are members of which user security groups having access permissions to which network objects, a learned actual access subsystem operative to learn actual access history of users in the enterprise to the network objects and to provide indications of which users have had actual access to which network objects, and a computer security policy administration subsystem, receiving indications from the learned access permission subsystem and the learned actual access subsystem and being operative to automatically replace pre-selected user-security group-based access permissions with at least partially actual access-based access permissions without disruptiType: GrantFiled: December 19, 2017Date of Patent: June 11, 2019Assignee: VARONIS SYSTEMS, INC.Inventors: Yakov Faitelson, Ohad Korkus, Ophir Kretzer-Katzir, David Bass
-
Patent number: 10296596Abstract: A method for characterizing data elements in an enterprise including ascertaining at least one of an access metric and a data identifier for each of a plurality of data elements and employing the at least one of an access metric and a data identifier to automatically apply a metatag to ones of the plurality of data elements.Type: GrantFiled: May 26, 2011Date of Patent: May 21, 2019Assignee: VARONIS SYSTEMS, INC.Inventors: Yakov Faitelson, Ohad Korkus, Ophir Kretzer-Katzir, David Bass