Patents by Inventor Avi Chesla

Avi Chesla has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20160057166
    Abstract: A method and system for adaptively securing a protected entity against a potential advanced persistent threat (APT) are provided. The method includes probing a plurality of resources in a network prone to be exploited by an APT attacker; operating at least one security service configured to output signals indicative of APT related activity of each of the plurality of probed resources; generating at least one security event respective of the output signals; determining if the at least one security event satisfies at least one workflow rule; and upon determining that the at least one security event satisfies the at least one workflow rule, generating at least one action with respect to the potential APT attack.
    Type: Application
    Filed: July 15, 2015
    Publication date: February 25, 2016
    Applicant: EMPOW CYBER SECURITY LTD.
    Inventor: Avi Chesla
  • Publication number: 20160021056
    Abstract: A system and method for adaptively securing a protected entity against cyber-threats are presented. The method includes selecting at least one security application configured to handle a cyber-threat, wherein the at least one security application executes a plurality of security services assigned to the at least one security application; determining at least one workflow rule respective of the at least one security application; receiving a plurality of signals from the plurality of security services, wherein each signal of the plurality of signals is generated with respect to a potential cyber-threat; generating at least one security event respective of the plurality of received signals; checking determining if the at least one security event satisfies the at least one workflow rule; and upon determining that the at least one security event satisfies the workflow rule, generating at least one action with respect to the potential cyber-threat.
    Type: Application
    Filed: February 5, 2015
    Publication date: January 21, 2016
    Applicant: Empow Cyber Security Ltd.
    Inventor: Avi Chesla
  • Publication number: 20160021135
    Abstract: A system and method for adaptively securing a protected entity against cyber-threats. The method comprises: determining, based on at least one input feature, at least one normalization function, wherein the at least one input feature defines an attribute of a data flow to be evaluated by the SDE; receiving at least one engine rule describing an anomaly to be evaluated; and creating an inference system including at least one inference unit, wherein each inference unit is determined based on one of the received at least one engine rule, wherein the inference system computes a score of anomaly (SoA) respective of the at least one input feature.
    Type: Application
    Filed: May 19, 2015
    Publication date: January 21, 2016
    Applicant: Empow Cyber Security Ltd.
    Inventors: Avi Chesla, Shlomi MEDALION
  • Patent number: 9210180
    Abstract: A method and system for separation of traffic processing in a software defined network (SDN). The method comprises allocating a first group of computing resources of a computing farm to a trusted zone and a second group of computing resources to an un-trusted zone; assigning the computing resources in the first group to a first ADC and the computing resources in the second group with a second ADC; triggering a zoning mode in the computing frame to mitigate a potential cyber-attack; and causing at least one network element in the SDN to divert traffic from a trusted client to the first group of computing resources and traffic from an un-trusted client to the second group of computing resources based on a plurality of zoning rules implemented by the at least one network element.
    Type: Grant
    Filed: January 17, 2013
    Date of Patent: December 8, 2015
    Assignee: Radware Ltd.
    Inventors: Yehuda Zisapel, Avi Chesla, Shay Naeh, David Aviv, Ehud Doron
  • Patent number: 9130977
    Abstract: A system and method for separation of traffic processing in a computing farm. The method comprises allocating a first group of computing resources of the computing farm to a trusted zone and a second group of computing resources to an un-trusted zone, wherein the computing resources in the first group are allocated to ensure at least service-level agreements (SLA) guaranteed to a group of trusted clients; determining, based on a plurality of security risk indication parameters, if a client associated with an incoming traffic is a trusted client or an un-trusted client; forwarding the incoming traffic to the second group of computing resources when the client is determined to be an un-trusted client; and diverting the incoming traffic to the first group of computing resources when the client is determined to be a trusted client, thereby ensuring at least the SLA guaranteed to the trusted client.
    Type: Grant
    Filed: January 17, 2013
    Date of Patent: September 8, 2015
    Assignee: Radware, Ltd.
    Inventors: Yehuda Zisapel, Avi Chesla, Shay Naeh, David Aviv
  • Patent number: 9055006
    Abstract: A method for mitigating of denial of service (DoS) attacks in a software defined network (SDN). The method comprises receiving a DoS attack indication performed against at least one destination server; programming each network element in the SDN to forward a packet based on a diversion value designated in a packet diversion field, upon reception of the DoS attack indication; instructing at least one peer network element in the SDN to mark a diversion field in each packet in the incoming traffic addressed to the destination server to allow diversion of the packet to a security server; and instructing edge network elements in the SDN to unmark the diversion field of each packet output by the security server, wherein each network element in the SDN is programmed to forward the unmarked packets processed by the security server to the at least one destination server.
    Type: Grant
    Filed: June 10, 2013
    Date of Patent: June 9, 2015
    Assignee: Radware, Ltd.
    Inventors: Avi Chesla, Ehud Doron
  • Publication number: 20150154494
    Abstract: A method and system for configuring a behavioral network intelligence system using a network monitoring programming language are provided. The method includes defining at least one target of a traffic segment to be monitored using at least one application path attribute of an application, wherein the application is accessed via at least one user device connected to a network, wherein the at least one application path attribute is defined respective of an application path keyword and an application path assessment keyword; and defining at least one condition representing the behavior of the at least one application path attribute of the application, the at least one target and the at least one condition can be interpreted by a monitoring system to allow for determining a behavioral impact of the application on the network.
    Type: Application
    Filed: December 4, 2014
    Publication date: June 4, 2015
    Applicant: RADWARE, LTD.
    Inventors: Lev MEDVEDOVSKY, David AVIV, Avi CHESLA
  • Publication number: 20150156086
    Abstract: A method and system for determining the behavioral impact of applications and their respective users on a network carrier are provided. The method includes receiving data collected by at least one deep packet inspection (DPI) engine; classifying the received data at least per an application path respective of each of the applications; generating an application path profile data structure using the collected data; and generating, responsive to at least one behavioral rule, at least one degree of fulfillment (DoF) for the application path based on contents of the application path profile data structure, wherein the at least DoF defines an association of the application path with at least one behavior group, wherein the behavior group determines the behavioral impact of an application represented by the application path.
    Type: Application
    Filed: December 4, 2014
    Publication date: June 4, 2015
    Applicant: RADWARE, LTD.
    Inventors: Avi CHESLA, David AVIV, Lev MEDVEDOVSKY
  • Publication number: 20150089566
    Abstract: A method for performing an escalation security policy in a software defined network (SDN) includes receiving at least one attack indication performed against at least one destination server; upon determination that an attack is being performed against the at least one destination server, for each client sending traffic to the at least one destination server: determining a risk state for a user of the each client; obtaining an escalation security policy respective of the determined risk state of the user, wherein the escalation security policy defines a sequence of at least one challenge action for challenging the each client, an order and at least one condition for execution of the sequence of at least one challenge action; and causing network elements of the SDN to divert incoming traffic from the each client to security servers connected to the SDN and configured to perform the at least one challenge action.
    Type: Application
    Filed: September 24, 2013
    Publication date: March 26, 2015
    Applicant: RADWARE, LTD.
    Inventor: Avi CHESLA
  • Publication number: 20140373143
    Abstract: A method and system for detecting and mitigating attacks performed using a cryptographic protocol are provided. The method comprises establishing an encrypted connection with the client using the cryptographic protocol, upon receiving an indication about a potential attack; receiving an inbound traffic from a client, wherein the inbound traffic is originally directed to a protected entity; analyzing application layer attributes of only the inbound traffic received on the encrypted connection to detect at least one encrypted attack; and causing to establish a new encrypted connection between the client and the protected entity, if the at least one encrypted attack at the application layer has not been detected.
    Type: Application
    Filed: September 4, 2014
    Publication date: December 18, 2014
    Applicant: RADWARE, LTD.
    Inventors: Avi Chesla, Yosefa Shulman, Ziv Ichilov, Iko Azoulay
  • Publication number: 20140283051
    Abstract: A method for efficient mitigation of denial of service (DoS) attacks in a virtual network. The method maintains a security service level agreement (SLA) guaranteed to protected objects. The method comprises ascertaining that a denial of service (DoS) attack is performed in the virtual network; checking if the DoS attack affects at least one physical machine hosting at least one protected object, wherein the protected object is provisioned with at least a guaranteed security service level agreement (SLA); determining, by a central controller of the virtual network, an optimal mitigation action to ensure the at least one security SLA guaranteed to the least one protected object; and executing the determined optimal mitigation action to mitigate the DoS attack, wherein the optimal mitigation action is facilitated by means of resources of the virtual network.
    Type: Application
    Filed: March 14, 2013
    Publication date: September 18, 2014
    Applicant: RADWARE, LTD.
    Inventors: Ehud DORON, Avi CHESLA
  • Patent number: 8832831
    Abstract: A method and security system for detecting and mitigating encrypted denial-of-service (DoS) attacks. The system includes a DoS defense (DoSD) module configured to detect an encrypted DoS attack in an inbound traffic by analyzing attributes only in the inbound traffic that relate to at least one of a network layer and an application layer, wherein the DoSD module is further configured to mitigate a detected encrypted attack, the inbound traffic originates at a client and is addressed to a protected server; and a cryptographic protocol engine (CPE) configured to establish a new encrypted session between the client and the security system, decrypt requests included in the inbound traffic, and send encrypted responses to the client over the new encrypted session between the client and the security system.
    Type: Grant
    Filed: March 21, 2012
    Date of Patent: September 9, 2014
    Assignee: Radware, Ltd.
    Inventors: Avi Chesla, Yosefa Shulman, Ziv Ichilov, Iko Azoulay
  • Publication number: 20130333029
    Abstract: A method for mitigating of denial of service (DoS) attacks in a software defined network (SDN). The method comprises receiving a DoS attack indication performed against at least one destination server; programming each network element in the SDN to forward a packet based on a diversion value designated in a packet diversion field, upon reception of the DoS attack indication; instructing at least one peer network element in the SDN to mark a diversion field in each packet in the incoming traffic addressed to the destination server to allow diversion of the packet to a security server; and instructing edge network elements in the SDN to unmark the diversion field of each packet output by the security server, wherein each network element in the SDN is programmed to forward the unmarked packets processed by the security server to the at least one destination server.
    Type: Application
    Filed: June 10, 2013
    Publication date: December 12, 2013
    Inventors: Avi Chesla, Ehud Doron
  • Publication number: 20130329734
    Abstract: A method for providing value added services (VAS) in a software defined network (SDN). The method comprises determining which value added services and their order should be assigned to an incoming traffic; determining for each of the one or more value added services their respective servers providing the value added services and assigning a unique diversion value to each server; instructing at least one peer network element to set a diversion field in each packet in the incoming traffic with a diversion value corresponding to a server providing a first value added service of the one or more value added services; and instructing each edge network element to set the diversion field of each packet output by the server to designate a destination node for the packet, wherein the destination node is any one of the destination server and a server providing a subsequent value added service.
    Type: Application
    Filed: June 10, 2013
    Publication date: December 12, 2013
    Inventors: Avi Chesla, Ehud Doron
  • Publication number: 20130283373
    Abstract: A system and method for separation of traffic processing in a computing farm. The method comprises allocating a first group of computing resources of the computing farm to a trusted zone and a second group of computing resources to an un-trusted zone, wherein the computing resources in the first group are allocated to ensure at least service-level agreements (SLA) guaranteed to a group of trusted clients; determining, based on a plurality of security risk indication parameters, if a client associated with an incoming traffic is a trusted client or an un-trusted client; forwarding the incoming traffic to the second group of computing resources when the client is determined to be an un-trusted client; and diverting the incoming traffic to the first group of computing resources when the client is determined to be a trusted client, thereby ensuring at least the SLA guaranteed to the trusted client.
    Type: Application
    Filed: January 17, 2013
    Publication date: October 24, 2013
    Applicant: RADWARE, LTD.
    Inventors: Yehuda ZISAPEL, Avi CHESLA, Shay NAEH, David AVIV
  • Publication number: 20130283374
    Abstract: A method and system for separation of traffic processing in a software defined network (SDN). The method comprises allocating a first group of computing resources of a computing farm to a trusted zone and a second group of computing resources to an un-trusted zone; assigning the computing resources in the first group to a first ADC and the computing resources in the second group with a second ADC; triggering a zoning mode in the computing frame to mitigate a potential cyber-attack; and causing at least one network element in the SDN to divert traffic from a trusted client to the first group of computing resources and traffic from an un-trusted client to the second group of computing resources based on a plurality of zoning rules implemented by the at least one network element.
    Type: Application
    Filed: January 17, 2013
    Publication date: October 24, 2013
    Applicant: RADWARE, LTD.
    Inventors: Yehuda ZISAPEL, Avi CHESLA, Shay NAEH, David AVIV, Ehud DORON
  • Patent number: 8566936
    Abstract: A method and system for protecting a protected entity using a multi-dimensional protection surface are provided. According to various embodiments, the multi-dimensional protection surface is generated by correlating multiple inputs related to the at least one detected attack. The inputs include at least one input identifying the detected attack and another input identifying each attack tool that performs the detected attack. The generated protection multi-dimensional surface includes protection points, where each such point defines at least one attack mitigation action to mitigate the detected attack.
    Type: Grant
    Filed: November 29, 2011
    Date of Patent: October 22, 2013
    Assignee: Radware, Ltd.
    Inventor: Avi Chesla
  • Publication number: 20130254879
    Abstract: A method and security system for detecting and mitigating encrypted denial-of-service (DoS) attacks. The system includes a DoS defense (DoSD) module configured to detect an encrypted DoS attack in an inbound traffic by analyzing attributes only in the inbound traffic that relate to at least one of a network layer and an application layer, wherein the DoSD module is further configured to mitigate a detected encrypted attack, the inbound traffic originates at a client and is addressed to a protected server; and a cryptographic protocol engine (CPE) configured to establish a new encrypted session between the client and the security system, decrypt requests included in the inbound traffic, and send encrypted responses to the client over the new encrypted session between the client and the security system.
    Type: Application
    Filed: March 21, 2012
    Publication date: September 26, 2013
    Applicant: RADWARE, LTD.
    Inventors: Avi Chesla, Yosefa Shulman, Ziv Ichilov, Iko Azoulay
  • Patent number: 8510834
    Abstract: A distributed security system wherein intelligent security agents (i.e., agent devices) share security incident information between themselves via a controller. An adaptive security decision making involving network worms (non-SMTP worms) and DoS floods attacks is also described; wherein the Worms and DoS flood digital signatures are generated to assist in intrusion prevention process.
    Type: Grant
    Filed: October 9, 2007
    Date of Patent: August 13, 2013
    Assignee: Radware, Ltd.
    Inventor: Avi Chesla
  • Publication number: 20130139214
    Abstract: A method and system for protecting a protected entity using a multi-dimensional protection surface. The method comprises detecting at least one potential attack against the protected entity in incoming data traffic directed to the protected entity; detecting a type of each attack tool committing the at least one potential attack; generating a multi-dimensional protection surface by correlating a plurality of inputs related to the at least one detected attack, wherein the plurality of inputs include at least a first input identifying the at least one detected attack and a second input identifying each attack tool that performs the at least one detected attack, wherein the protection multi-dimensional surface includes at least one protection point that defines at least one attack mitigation action to mitigate the at least one detected attack; and executing the at least one attack mitigation action defined in the multi-dimensional protection surface.
    Type: Application
    Filed: November 29, 2011
    Publication date: May 30, 2013
    Applicant: RADWARE, LTD.
    Inventor: Avi CHESLA