Patents by Inventor Chen Erlich

Chen Erlich has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20260259985
    Abstract: A method for detecting an attempt to side-load a malicious Dynamic Link Library (DLL) includes identifying a load image event in a computer system, the load image event indicating that an operating system has loaded an application together with a DLL. An event filtering criterion that assesses signatures of the application and the DLL is applied to the load image event. A profile filtering criterion that assesses prevalence of characteristics of the DLL within the computer system is applied to the load image event. Responsively to meeting both the event filtering criterion and the profile filtering criterion, a determination is made that the load image event is suspected of indicating a DLL side-loading attack.
    Type: Application
    Filed: April 27, 2026
    Publication date: September 3, 2026
    Inventor: Chen Erlich
  • Publication number: 20260037629
    Abstract: A method for detecting a cyber-attack includes identifying an event occurring in a computer belonging to a computer system, the event including loading of an application to memory together with a Dynamic Link Library (DLL). A filtering criterion is applied to the event, to verify that (i) the application and the DLL are loaded from the same folder, (ii) the application is signed and verified and (iii) the DLL does not have a valid signature. Responsively to meeting the filtering criterion, a profiling criterion is applied to the event, to verify that prevalences of defined characteristics of the DLL in the computer system are below defined prevalence levels. Responsively to meeting the profiling criterion, a decision is made that the DLL is suspected of being malicious.
    Type: Application
    Filed: July 31, 2024
    Publication date: February 5, 2026
    Inventor: Chen Erlich
  • Publication number: 20260030346
    Abstract: A system for autonomous cyber-security investigation includes an input interface and one or more processors. The input interface receives security-related inputs detected in a computer system. The processors construct, based on the security-related inputs, a graph including nodes and edges. The nodes include (i) appearance-nodes representing occurrences in the computer system having respective times-of-occurrence and (ii) artifact-nodes representing time-static features found in the security-related inputs. The edges represent relationships between the nodes.
    Type: Application
    Filed: July 25, 2024
    Publication date: January 29, 2026
    Inventors: Erez Levy, Yuval Zan, Chen Erlich, Netanel Rimer