Patents by Inventor Daniel DAVRAEV

Daniel DAVRAEV has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 12580944
    Abstract: The disclosure focuses on using a risk inheritance system to actively prevent unauthorized and compromising activity within a cloud computing system by causing user risk scores to be inherited across downstream cloud entities within the cloud computing system. The risk inheritance system ensures that users with risky user risk scores are unable to circumvent the security measures of the cloud computing system through propagation events. For instance, the risk inheritance system assigns user risk scores to be inherited from a cloud entity of a user to another cloud entity, including other users and service principals, based on detecting the user initiating a propagation event. This way, the risk inheritance system improves the efficiency of the cloud computing system by ensuring that cloud entities are assigned accurate user risk scores.
    Type: Grant
    Filed: September 19, 2023
    Date of Patent: March 17, 2026
    Assignee: Microsoft Technology Licensing, LLC
    Inventors: Daniel Davraev, Josef Weizman, Ram Haim Pliskin
  • Publication number: 20260073047
    Abstract: Malicious activity detection is enabled for cloud computing platforms. A first log comprising a record of a first control plane operation executed by a cloud application associated with an entity is obtained. A plurality of second logs, each comprising a record of a respective second control plane operation executed in association with the entity, is obtained. A first property set is generated based on the first log and a second property set is generated based on the plurality of second logs. A malicious activity score indicative of a degree to which the first control plane operation is anomalous with respect to the entity is determined based on the first property set and the second property set. A determination that the first control plane operation potentially corresponds to malicious activity is made based on the malicious activity score and a security alert is generated.
    Type: Application
    Filed: November 13, 2025
    Publication date: March 12, 2026
    Inventors: Shalom Shay SHAVIT, Ram Haim PLISKIN, Daniel DAVRAEV
  • Patent number: 12443708
    Abstract: Systems and techniques for reduction of security detection false positives are described herein. Suspicious activity data is obtained for an operation. Operation data is obtained for the operation. It is determined that the operation is related to a parent operation that has not triggered an alert. The operation is cleared from the suspicious activity data.
    Type: Grant
    Filed: February 13, 2023
    Date of Patent: October 14, 2025
    Assignee: Microsoft Technology Licensing, LLC
    Inventors: Shalom Shay Shavit, Ram Haim Pliskin, Daniel Davraev
  • Patent number: 12430427
    Abstract: A recovery instruction pertaining to a resource is detected. The recovery instruction is matched with a delete instruction that caused the resource to enter a soft-deleted. A mismatch between a first user account associated with the recovery instruction and a second user account associated with the delete instruction is determined. A mitigation action is performed based on determining the mismatch between the first user account and the second user account.
    Type: Grant
    Filed: December 19, 2022
    Date of Patent: September 30, 2025
    Assignee: Microsoft Technology Licensing, LLC
    Inventors: Daniel Davraev, Shalom Shay Shavit, Ram Haim Pliskin
  • Publication number: 20250284797
    Abstract: Some embodiments provide attacker-focused granular disruption functionality to detect and defend against cyberattacks. An embodiment observes that a user account or a user session has executed one or more precursor events but has not executed an incrimination action. The incrimination action is more likely, by at least a specified amount, to be performed by an attacker-driven account or session than by a non-attacker-driven account or session. Performance of the incrimination action is preemptively blocked, without disabling the account or session. The block is focused on the incrimination action, and in some scenarios the embodiment also blocks performance of similar actions. After an attempt by the account or session to perform the blocked incrimination action, larger blocks on activity are enforced, up to and including disablement, because the attempt indicates strongly that the account or session is driven by an attacker.
    Type: Application
    Filed: March 6, 2024
    Publication date: September 11, 2025
    Inventors: Hani Hana NEUVIRTH, Jonatan ZUKERMAN, Tal Joseph MAOR, Pawel Marek PARTYKA, Daniel DAVRAEV, Eyal HAIK
  • Publication number: 20250097251
    Abstract: The disclosure focuses on using a risk inheritance system to actively prevent unauthorized and compromising activity within a cloud computing system by causing user risk scores to be inherited across downstream cloud entities within the cloud computing system. The risk inheritance system ensures that users with risky user risk scores are unable to circumvent the security measures of the cloud computing system through propagation events. For instance, the risk inheritance system assigns user risk scores to be inherited from a cloud entity of a user to another cloud entity, including other users and service principals, based on detecting the user initiating a propagation event. This way, the risk inheritance system improves the efficiency of the cloud computing system by ensuring that cloud entities are assigned accurate user risk scores.
    Type: Application
    Filed: September 19, 2023
    Publication date: March 20, 2025
    Inventors: Daniel DAVRAEV, Josef WEIZMAN, Ram Haim PLISKIN
  • Publication number: 20250088517
    Abstract: The disclosure focuses on using a context-based insight system to determine security incident reports that include security incident insights and remediation actions based on various combinations of security alerts in cloud computing systems. The context-based insight system uses a security alert generative language model (GLM) to generate security incident reports based on correlated security alerts within a security incident and the attack-type contexts of those security alerts. By using the security alert GLM guided by attack-type contexts to generate security incident reports, the context-based insight system provides understandable text narratives that provide clear and accurate insights into security incidents including remediation actions to address the security incidents as a whole rather than just reporting individual security alerts of the security incident.
    Type: Application
    Filed: September 13, 2023
    Publication date: March 13, 2025
    Inventors: Daniel DAVRAEV, Idan Yehoshua HEN, Tamer SALMAN
  • Publication number: 20240380767
    Abstract: Malicious service provider activity detection is enabled. A first log is obtained. The first log comprises a record of a first control plane operation executed on behalf of a first entity. A service provider associated with the execution of the first control plane operation is identified. The service provider has privileges to execute control plane operations on behalf of the first entity. A first malicious activity score is determined based at least on the service provider. The first malicious activity score is indicative of a degree to which the first control plane operation is anomalous with respect to the first entity. A determination that the first control plane operation potentially corresponds to malicious activity is made based at least on the determined first malicious activity score. Responsive to determining that the first control plane operation potentially corresponds to malicious activity, a security alert is generated.
    Type: Application
    Filed: May 8, 2023
    Publication date: November 14, 2024
    Inventors: Daniel DAVRAEV, Shalom Shay SHAVIT, Hagai Ran KESTENBERG
  • Publication number: 20240330445
    Abstract: Malicious activity detection is enabled for cloud computing platforms. A first log comprising a record of a first control plane operation executed by a cloud application associated with an entity is obtained. A plurality of second logs, each comprising a record of a respective second control plane operation executed in association with the entity, is obtained. A first property set is generated based on the first log and a second property set is generated based on the plurality of second logs. A malicious activity score indicative of a degree to which the first control plane operation is anomalous with respect to the entity is determined based on the first property set and the second property set. A determination that the first control plane operation potentially corresponds to malicious activity is made based on the malicious activity score and a security alert is generated.
    Type: Application
    Filed: June 9, 2023
    Publication date: October 3, 2024
    Inventors: Shalom Shay SHAVIT, Ram Haim PLISKIN, Daniel DAVRAEV
  • Publication number: 20240311483
    Abstract: Methods, systems, and computer storage media for providing security incident management using a latent-context alert correlation engine in a security management system. Security incident management is provided using the latent-context alert correlation engine that is operationally integrated into the security management system. In operation, first security data of a first alert and second security data of a second alert are accessed. The first alert and the second alert do not share a common entity identifiable in a security graph. Using the first security data and the second security data, a determination is made that the first alert is connected to the second alert based on a latent-context connection. The latent-context connection is a known attack path connection that indirectly connects alerts. Based on determining that the first alert is connected to the second alert, a security incident is generated for the alert. A notification comprising the security incident is communicated.
    Type: Application
    Filed: March 14, 2023
    Publication date: September 19, 2024
    Inventors: Daniel DAVRAEV, Tamer Salman, Ram Haim Pliskin
  • Publication number: 20240273189
    Abstract: Systems and techniques for reduction of security detection false positives are described herein. Suspicious activity data is obtained for an operation. Operation data is obtained for the operation. It is determined that the operation is related to a parent operation that has not triggered an alert. The operation is cleared from the suspicious activity data.
    Type: Application
    Filed: February 13, 2023
    Publication date: August 15, 2024
    Inventors: Shalom Shay Shavit, Ram Haim Pliskin, Daniel Davraev
  • Publication number: 20240070271
    Abstract: A recovery instruction pertaining to a resource is detected. The recovery instruction is matched with a delete instruction that caused the resource to enter a soft-deleted. A mismatch between a first user account associated with the recovery instruction and a second user account associated with the delete instruction is determined. A mitigation action is performed based on determining the mismatch between the first user account and the second user account.
    Type: Application
    Filed: December 19, 2022
    Publication date: February 29, 2024
    Inventors: Daniel DAVRAEV, Shalom Shay SHAVIT, Ram Haim PLISKIN