Patents by Inventor Asaf Hecht

Asaf Hecht has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 12681844
    Abstract: Systems, methods, and apparatuses are disclosed for injecting secrets into a software instance environment. Techniques may include identifying code of an application from storage, analyzing the code to determine a secret associated with execution of the application, and monitoring the application running in one or more instances to determine a condition for the application to use the secret. Techniques may further include validating the condition for the application to use the secret based on an execution state of the application, and injecting the secret into the one or more instances, wherein the application can then access the secret and perform an operation using the secret in accordance with the determined condition.
    Type: Grant
    Filed: August 17, 2023
    Date of Patent: July 14, 2026
    Assignee: CyberArk Software Ltd.
    Inventors: Asaf Hecht, Emmanuel Ouanounou
  • Publication number: 20260163884
    Abstract: Disclosed herein are techniques for securing a real time communication session between at least two computing devices. Operations may include monitoring the communication session between the at least two computing devices associated with an organizational communication security service, validating, by the organizational communication security service, the communication session, determining, by the organizational communication security service, a security status of the communication session based on the real-time validation of the communication session, and performing, by the organizational communication security service, a security action based on the security status.
    Type: Application
    Filed: December 9, 2024
    Publication date: June 11, 2026
    Applicant: CyberArk Software Ltd.
    Inventors: Asaf HECHT, Roy Ben YOSEF, Jason YOKOTA
  • Patent number: 12591684
    Abstract: Disclosed embodiments relate to systems and methods for centrally analyzing and managing source code. Techniques include identifying, at a centralized resource in a network environment, a first source code; identifying the first source code as a candidate for an execution of an access control action; identifying, at the centralized resource, a security risk indication for the first source code, the security risk indication being based on permissions associated with a functionality of the first source code; performing, based on the security risk indication, at least one of: developing a least privilege set of permissions for the source code, or modifying the least privilege set of permissions.
    Type: Grant
    Filed: January 3, 2022
    Date of Patent: March 31, 2026
    Assignee: CyberArk Software Ltd.
    Inventor: Asaf Hecht
  • Patent number: 12554834
    Abstract: Described herein are methods, systems, and computer-readable storage media for dynamically configuring and deploying customizable secure wrappers. Techniques include identifying a code element and provisioning a first wrapper to execute the code element. Techniques further include allowing execution of the code element with the first wrapper, identifying a second wrapper for use in execution of the code element. The second wrapper is either customized for the code element or selected for the code element or both. Further, the code execution management system transitions from the first wrapper to the second wrapper, and allows execution of the code element with the second wrapper.
    Type: Grant
    Filed: December 21, 2021
    Date of Patent: February 17, 2026
    Assignee: CyberArk Software Ltd.
    Inventors: Mark Cherp, Nir Chako, Asaf Hecht
  • Publication number: 20250371135
    Abstract: Disclosed embodiments relate to systems and methods for dynamically reviewing managed session activity using machine learning models. Techniques include identifying a managed session between a network identity and a target resource; performing a reviewal process for the managed session, including identifying session data associated with the managed session; providing the session data and a context data as an input to at least one machine learning model; obtaining an output from the at least one machine learning model based on an analysis of the session data and the context data; and determining, based on the output, whether to perform a security action associated with the managed session.
    Type: Application
    Filed: May 29, 2024
    Publication date: December 4, 2025
    Applicant: CyberArk Software Ltd.
    Inventors: Asaf Hecht, Michael Balber, Daniel Alfasi
  • Patent number: 12363096
    Abstract: Techniques include securely accessing data associated with authorization of an identity, the identity being capable of accessing an access-controlled network resource based on assertion of an authentication credential to an entity associated with the access-controlled network resource; generating a secret data element based on the data associated with authorization of the identity and based on application of a first secret logic algorithm; and making the secret data element available to be embedded in the authentication credential. The entity associated with the access-controlled network resource is configured to: validate the identity based on the secret data element being included in the authentication credential; and access the data associated with authorization of the identity based on application of a second secret logic algorithm to the secret data element.
    Type: Grant
    Filed: May 23, 2022
    Date of Patent: July 15, 2025
    Assignee: CyberArk Software Ltd.
    Inventor: Asaf Hecht
  • Patent number: 12289334
    Abstract: Disclosed embodiments relate to systems and methods for composite risk scores for network resources. Techniques include retrieving data associated with multiple network resources. The retrieved data is used to perform a first assessment for each of the multiple network resources to estimate a vulnerability level for each of the multiple network resources. The retrieved dated is also used to perform a second assessment for each of the multiple network resources to estimate an importance level for each of the multiple network resources. Based on a result of the first assessment and a result of the second assessment, a composite risk score for each of the multiple network resources is determined. When needed, a security response is performed based on the determined composite risk score of a specific network resource among the multiple network resources.
    Type: Grant
    Filed: April 20, 2022
    Date of Patent: April 29, 2025
    Assignee: CyberArk Software, Ltd.
    Inventor: Asaf Hecht
  • Patent number: 12255889
    Abstract: Techniques include securely accessing data associated with at least one identity capable of accessing one or more access-controlled network resources; generating an intermediate value based on the data associated with the at least one identity; generating, based on application of a secret logic algorithm to the intermediate value, a secret data element; making available, the secret data element, to be embedded in an authentication credential associated with the at least one identity; identifying an attempt to change the authentication credential, the attempt including new authentication credential data to replace data in the authentication credential; validating, conditional on a determination whether the new authentication credential data includes the secret data element in a predefined location, the attempt to change the authentication credential; and determining, based on the validating, whether to perform a control action based on the new authentication credential data.
    Type: Grant
    Filed: November 24, 2021
    Date of Patent: March 18, 2025
    Assignee: CyberArk Software Ltd.
    Inventor: Asaf Hecht
  • Publication number: 20250061053
    Abstract: Systems, methods, and apparatuses are disclosed for injecting secrets into a software instance environment. Techniques may include identifying code of an application from storage, analyzing the code to determine a secret associated with execution of the application, and monitoring the application running in one or more instances to determine a condition for the application to use the secret. Techniques may further include validating the condition for the application to use the secret based on an execution state of the application, and injecting the secret into the one or more instances, wherein the application can then access the secret and perform an operation using the secret in accordance with the determined condition.
    Type: Application
    Filed: August 17, 2023
    Publication date: February 20, 2025
    Applicant: CyberArk Software Ltd.
    Inventors: Asaf Hecht, Emmanuel Ouanounou
  • Patent number: 12143411
    Abstract: Disclosed embodiments relate to systems and methods for dynamically and proactively scanning a computing environment for application misconfiguration security threats. Techniques include identifying an application configured for network communications; analyzing a network security configuration of the application; identifying, based on the analyzing, a target network address that the application is configured to use to redirect a network device to a target network resource; comparing the target network address to a whitelist of trusted target network addresses; assessing, based on the comparing, whether the network security configuration is misconfigured; and determining, based on the assessment, whether to provide a configuration validation status for the application.
    Type: Grant
    Filed: April 7, 2020
    Date of Patent: November 12, 2024
    Assignee: CyberArk Software Ltd.
    Inventors: Omer Tsarfati, Asaf Hecht
  • Patent number: 12028366
    Abstract: Disclosed embodiments relate to systems and methods for dynamically performing entity-specific security assessments for entities of virtualized network environments. Techniques include identifying an entity associated with a virtualized network environment, identifying a plurality of security factors, determining entity-specific weights to the plurality of security factors, and generating a composite exposure assessment for the entity.
    Type: Grant
    Filed: March 11, 2021
    Date of Patent: July 2, 2024
    Assignee: CyberArk Software Ltd.
    Inventors: Niv Rabin, Michael Balber, Noa Moyal, Asaf Hecht, Gal Naor
  • Patent number: 11997197
    Abstract: Disclosed embodiments relate to systems and methods for securely providing secrets. Techniques include receiving, from an entity, trigger information indicative of an action to be performed by at least one service based on the trigger information; identifying at least one secret expected to be used by the at least one service to perform the action, the at least one secret being identified based on information correlating the trigger information to the at least one secret; and causing the at least one secret to be provided to the at least one service, wherein the at least one secret is provided to the at least one service independent of any request for the at least one secret.
    Type: Grant
    Filed: June 29, 2023
    Date of Patent: May 28, 2024
    Assignee: CyberArk Software Ltd.
    Inventors: Emmanuel Ouanounou, Asaf Hecht
  • Patent number: 11941109
    Abstract: Described herein are methods, systems, and computer-readable storage media for generation of a secure and dynamically mutable operating system. Techniques include receiving a request to execute an application causing instantiation of an operating system by identifying one or more needed modules that include core kernel modules and operating system service modules that are dynamically plugged-in or unplugged based on the execution of the application. Techniques may further include assigning a separate memory space with a separate virtual address for each of the one or more modules, generating a unique cryptographic key for each of the one or more modules, storing each virtual address and corresponding unique cryptographic key together. Further the operating system generation system encrypts each of the one or more modules using their corresponding unique cryptographic key.
    Type: Grant
    Filed: December 21, 2021
    Date of Patent: March 26, 2024
    Assignee: CYBERARK SOFTWARE LTD.
    Inventors: Mark Cherp, Nir Chako, Asaf Hecht
  • Patent number: 11822670
    Abstract: Disclosed embodiments relate to systems and methods for automatically detecting and addressing security risks in code segments. Techniques include accessing a plurality of code segments developed for execution in a network environment, automatically identifying a first code segment from the plurality of code segments for analysis, automatically performing a first code-level security risk assessment for the first code segment, and determining a first security risk level for the first code segment based on the application programming interface risk level. The first code-level security risk assessment may be performed based on at least one of an application programming interface risk level, an embedded credentials risk level, and a target resource risk level. Further techniques may include determining a second security risk level for a modified version of the first code segment; and enabling a comparison between the first security risk level and the second security risk level.
    Type: Grant
    Filed: March 20, 2020
    Date of Patent: November 21, 2023
    Assignee: CyberArk Software Ltd.
    Inventors: Asaf Hecht, Hadas Elkabir
  • Patent number: 11743032
    Abstract: Described herein are methods, systems, and computer-readable storage media for participating in a validation process with the host computing device. Techniques include receiving, from the host computing device, a second key that is part of a cryptographic key pair comprising a first key and the second key. Techniques further include, encrypting, using the second key and as part of the validation process, data at the peripheral device and sending the encrypted data to the host computing device. Further, the host computing device validates an identity of the peripheral device based on a decryption, using the first key, of the encrypted data.
    Type: Grant
    Filed: January 25, 2022
    Date of Patent: August 29, 2023
    Assignee: CyberArk Software Ltd.
    Inventors: Omer Tsarfati, Asaf Hecht
  • Patent number: 11716326
    Abstract: Disclosed embodiments relate to systems and methods for securing the use of temporary access tokens in network environments. Techniques include identifying a request for an action involving a target network resource requiring a temporary access token; receiving, from the target network resource, a temporary access token; storing the temporary access token separate from the network identity; generating a customized replacement token having an attribute different from the temporary access token such that the customized replacement token cannot be used directly with the target network resource; providing the customized replacement token to the network identity; monitoring use of the customized replacement token to detect an activity identified as being at least one of potentially anomalous or potentially malicious; receiving an access request to access the target network resource; and based on the detected activity, denying the access request from the network identity.
    Type: Grant
    Filed: February 16, 2022
    Date of Patent: August 1, 2023
    Assignee: CyberArk Software Ltd.
    Inventors: Omer Tsarfati, Asaf Hecht
  • Publication number: 20230214533
    Abstract: Disclosed embodiments relate implementing a runtime-based permissions management layer for application programming interface (API) calls. Techniques include identifying an application having a plurality of application programming interface (API) calls associated with the application; identifying, based on the application, a reference sequencing profile associated with the plurality of API calls; allowing at least one API call of a first group of API calls to be performed based on the reference sequencing profile; allowing at least one API call of a second group of API calls to be performed based on the reference sequencing profile; and denying the at least one API call of the first group of API calls.
    Type: Application
    Filed: March 9, 2023
    Publication date: July 6, 2023
    Applicant: CyberArk Software Ltd.
    Inventor: Asaf HECHT
  • Publication number: 20230205571
    Abstract: Disclosed embodiments relate to systems and methods for analysis of data associated with software instances. Techniques include obtaining data associated with a software instance; archiving delta data associated with software instance; analyzing one more previous states of the software instance based on the archived delta data; and performing a security action based on the analysis of the one or more previous states of the software instance based on the archived delta data.
    Type: Application
    Filed: February 27, 2023
    Publication date: June 29, 2023
    Applicant: CyberArk Software Ltd.
    Inventor: Asaf HECHT
  • Publication number: 20230195882
    Abstract: Described herein are methods, systems, and computer-readable storage media for dynamically configuring and deploying customizable secure wrappers. Techniques include identifying a code element and provisioning a first wrapper to execute the code element. Techniques further include allowing execution of the code element with the first wrapper, identifying a second wrapper for use in execution of the code element. The second wrapper is either customized for the code element or selected for the code element or both. Further, the code execution management system transitions from the first wrapper to the second wrapper, and allows execution of the code element with the second wrapper.
    Type: Application
    Filed: December 21, 2021
    Publication date: June 22, 2023
    Applicant: CyberArk Software Ltd.
    Inventors: Mark CHERP, Nir CHAKO, Asaf HECHT
  • Publication number: 20230195883
    Abstract: Described herein are methods, systems, and computer-readable storage media for generation of a secure and dynamically mutable operating system. Techniques include receiving a request to execute an application causing instantiation of an operating system by identifying one or more needed modules that include core kernel modules and operating system service modules that are dynamically plugged-in or unplugged based on the execution of the application. Techniques may further include assigning a separate memory space with a separate virtual address for each of the one or more modules, generating a unique cryptographic key for each of the one or more modules, storing each virtual address and corresponding unique cryptographic key together. Further the operating system generation system encrypts each of the one or more modules using their corresponding unique cryptographic key.
    Type: Application
    Filed: December 21, 2021
    Publication date: June 22, 2023
    Applicant: CyberArk Software Ltd.
    Inventors: Mark CHERP, Nir CHAKO, Asaf HECHT