Patents by Inventor Dan Karpati

Dan Karpati has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 12613756
    Abstract: A system and method are provided for utilizing a service's Application Programming Interface (API) documentation, generating an OpenAPI specification for the API, enriching the OpenAPI specification with artificial intelligence (AI) generated explanatory notes, and integrating the enriched OpenAPI specification with an AI engine (e.g., a natural language model, large language model, etc.). This process may permit users to interact with the service through natural language.
    Type: Grant
    Filed: September 28, 2023
    Date of Patent: April 28, 2026
    Assignee: CHECK POINT SOFTWARE TECHNOLOGIES LTD.
    Inventors: Barak Kfir, Albert Havinson, Nofar Bardugo, Dan Karpati, Tamir Zegman
  • Patent number: 12483535
    Abstract: A computer device (referred to as a processing engine), system, and method are provided for refactoring an original security policy using an artificial intelligence (AI) engine including a large language model (LLM). The processing engine parses policy data converts the original security policy into a code representation and sends the converted code representation to the AI engine. The AI engine analyzes the original security policy by applying the LLM to the code representation and identifies policy insights that are sent to the processing engine.
    Type: Grant
    Filed: June 27, 2024
    Date of Patent: November 25, 2025
    Assignee: Check Point Software Technologies Ltd.
    Inventors: Barak Kfir, Nofar Bardugo, Dan Karpati, Eliyahu Hanokh Sandler, Tamir Zegman
  • Patent number: 12411947
    Abstract: Methods and devices are provided for differentiating between benign DNS data and malicious DNS data included in DNS traffic using an autoencoder. The autoencoder receives input DNS data and is trained to successfully encode the input DNS data when the input DNS data is benign DNS data and to fail to encode the input DNS data when the input DNS data is malicious DNS data. The autoencoder is trained using a modified loss function having a large weight when successfully encoding malicious DNS data.
    Type: Grant
    Filed: December 29, 2022
    Date of Patent: September 9, 2025
    Assignee: Check Point Software Technologies Ltd.
    Inventors: Erez Israel, Dan Karpati, Eitan Shterenbaum, Lior Goldman
  • Publication number: 20250110816
    Abstract: A system and method are provided for utilizing a service's Application Programming Interface (API) documentation, generating an OpenAPI specification for the API, enriching the OpenAPI specification with artificial intelligence (AI) generated explanatory notes, and integrating the enriched OpenAPI specification with an AI engine (e.g., a natural language model, large language model, etc.). This process may permit users to interact with the service through natural language.
    Type: Application
    Filed: September 28, 2023
    Publication date: April 3, 2025
    Applicant: CHECK POINT SOFTWARE TECHNOLOGIES LTD.
    Inventors: Barak KFIR, Albert HAVINSON, Nofar BARDUGO, Dan KARPATI, Tamir ZEGMAN
  • Publication number: 20250112963
    Abstract: A computer device (referred to as a processing engine), system, and method are provided for refactoring an original security policy using an artificial intelligence (AI) engine including a large language model (LLM). The processing engine parses policy data converts the original security policy into a code representation and sends the converted code representation to the AI engine. The AI engine analyzes the original security policy by applying the LLM to the code representation and identifies policy insights that are sent to the processing engine.
    Type: Application
    Filed: June 27, 2024
    Publication date: April 3, 2025
    Applicant: Check Point Software Technologies Ltd.
    Inventors: Barak KFIR, Nofar BARDUGO, Dan KARPATI, Eliyahu Hanokh SANDLER, Tamir ZEGMAN
  • Publication number: 20240220613
    Abstract: Methods and devices are provided for differentiating between benign DNS data and malicious DNS data included in DNS traffic using an autoencoder. The autoencoder receives input DNS data and is trained to successfully encode the input DNS data when the input DNS data is benign DNS data and to fail to encode the input DNS data when the input DNS data is malicious DNS data. The autoencoder is trained using a modified loss function having a large weight when successfully encoding malicious DNS data.
    Type: Application
    Filed: December 29, 2022
    Publication date: July 4, 2024
    Inventors: Erez Israel, Dan Karpati, Eitan Shterenbaum, Lior Goldman
  • Patent number: 11223623
    Abstract: There are disclosed techniques for use in providing security in a computer network. In one embodiment, the techniques comprise a method including multiple steps. The method comprises receiving user access data characterizing user access with a protected resource within a computer network. The method also comprises evaluating the user access data to extract information therefrom that describes user access with respect to a feature of user access. The method also comprises determining a cardinality value in connection with the feature based on the extracted information and a maximum cardinality threshold. It should be appreciated that the cardinality value is limited by the maximum cardinality threshold such that the cardinality value cannot exceed the maximum cardinality threshold. The method also comprises presenting the cardinality value for facilitating fraud detection.
    Type: Grant
    Filed: June 30, 2016
    Date of Patent: January 11, 2022
    Assignee: EMC IP Holding Company LLC
    Inventors: Eyal Kolman, Assaf Mendelson, Eugene Gulko, Dan Karpati
  • Patent number: 10367835
    Abstract: Methods and apparatus are provided for detecting suspicious network activity by new devices. An exemplary method comprises: obtaining network event data for a given entity that comprises a user or a user device; determining a number of distinct other entities associated with the given entity during a predefined short time window, wherein the distinct other entities comprise user devices used by the user if the given entity comprises a user and comprise users of the user device if the given entity comprises a user device; determining a number of distinct other entities associated with the given entity during a predefined longer time window; and assigning a risk score to the given entity based on (i) the number during the predefined short time window relative to the number during the predefined longer time window, and/or (ii) the number during the predefined short time window relative to a predefined number.
    Type: Grant
    Filed: June 24, 2016
    Date of Patent: July 30, 2019
    Assignee: EMC IP Holding Company LLC
    Inventors: Kineret Raviv, Dan Karpati, Eyal Kolman, Ofri Mann, Alon Kaufman
  • Publication number: 20080022392
    Abstract: In the establishment of a VPN tunnel, a VPN gateway is responsible for resolving user and group attribute overlaps and conflicts when more than one AAA server is accessed during authentication and authorization. An IPSec Aggregator is provided with a governing policy that anticipates such conflicts and sets out precedence rules and alternative values of attributes.
    Type: Application
    Filed: July 5, 2006
    Publication date: January 24, 2008
    Inventors: Dan Karpati, Alon Zilberman, Eitan Ben Amos, Ido Halevi