Patents by Inventor Dmitry Babich
Dmitry Babich has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Publication number: 20260189508Abstract: Systems, methods, and computer readable medium are disclosed for load balancing network traffic. Load balancing network traffic includes receiving at a particular server among a plurality of candidate servers, one of a plurality of probes sent from a client device to the plurality of candidate servers; interpreting, at the particular server, the received probe to recognize that the received probe is a precursor to a persistent connection between the particular server and the client device; determining that a prospective connection between the particular server and the client device would be sub-optimal; and transmitting a biased response from the particular server to the client device to discourage establishment of the persistent connection between the client device and the particular server.Type: ApplicationFiled: October 24, 2025Publication date: July 2, 2026Applicant: CATO NETWORKS LTDInventors: Mark KAPLAN, Aviram KATZENSTEIN, Dmitry BABICH, David GOLDBERGER, Eyal HEIMAN
-
Publication number: 20260186764Abstract: Systems, methods, and computer readable medium are disclosed for altering network connections during maintenance periods. Altering network connections during maintenance periods includes monitoring via a cloud service, a network of distributed servers and client devices, the monitoring including maintaining records of software upgrade schedules for the servers and existing tunnels between the client devices and the servers; receiving at the cloud service a request to upgrade software on a particular server; in response to the request, scheduling the software upgrade; accessing the records to identify an existing tunnel between a client device and the particular server; prior to the scheduled upgrade, accessing the records to identify an alternative server to which existing tunnel traffic can be directed during the upgrade; and following identification and prior to the scheduled upgrade, rerouting network traffic flow from the client to the alternative server to thereby avoid a communication blip.Type: ApplicationFiled: October 31, 2025Publication date: July 2, 2026Applicant: CATO NETWORKS LTDInventors: Aviram KATZENSTEIN, Dmitry Babich, David Goldberger, Eyal Heiman, Raz Ashkenazi
-
Publication number: 20260189611Abstract: Systems, methods, and computer readable medium are disclosed for real-time dynamic policy revisions.Type: ApplicationFiled: October 31, 2025Publication date: July 2, 2026Applicant: CATO NETWORKS LTDInventors: Eyal HEIMAN, Ofir AGASI, Mark KAPLAN, Elad MENAHEM, Rotem SHAMIR, Dmitry BABICH, Peter NOVIKOV, Avraham GRUDA, Noa BARON, Uri SIVAN
-
Publication number: 20260189981Abstract: Systems, methods, and computer-readable media are described for facilitating network synchronization within a network comprising multiple distributed server clusters connected to various edge devices. The synchronization process involves maintaining multiple copies of a routing table, which are distributed across the locations of the server clusters and edge devices. When a connectivity change occurs and is detected by at least one server in the distributed server clusters, this change is represented as a delta in the routing table. The delta is then distributed across the server clusters and edge devices to update and synchronize all copies of the routing table, ensuring consistency across the network.Type: ApplicationFiled: October 24, 2025Publication date: July 2, 2026Applicant: CATO NETWORKS LTD.Inventors: Aviram KATZENSTEIN, Dmitry BABICH
-
Publication number: 20260189483Abstract: Systems, methods, and computer-readable media are described for facilitating network synchronization within a network comprising multiple distributed server clusters connected to various edge devices. The synchronization process involves maintaining multiple copies of a routing table, which are distributed across the locations of the server clusters and edge devices. When a connectivity change occurs and is detected by at least one server in the distributed server clusters, this change is represented as a delta in the routing table. The delta is then distributed across the server clusters and edge devices to update and synchronize all copies of the routing table, ensuring consistency across the network.Type: ApplicationFiled: October 24, 2025Publication date: July 2, 2026Applicant: CATO NETWORKS LTDInventors: Tomer DOITSHMAN, Rina BRUTER, Dolev MANASSEN, Aviv ABELSON, Rotem NAAR SHAMIR, Dmitry BABICH, Elad MENAHEM, Mark KAPLAN
-
Publication number: 20260189608Abstract: Systems, methods, and computer-readable media are described for facilitating network synchronization within a network comprising multiple distributed server clusters connected to various edge devices. The synchronization process involves maintaining multiple copies of a routing table, which are distributed across the locations of the server clusters and edge devices. When a connectivity change occurs and is detected by at least one server in the distributed server clusters, this change is represented as a delta in the routing table. The delta is then distributed across the server clusters and edge devices to update and synchronize all copies of the routing table, ensuring consistency across the network.Type: ApplicationFiled: October 24, 2025Publication date: July 2, 2026Applicant: CATO NETWORKS LTDInventors: Raz ASHKENAZI, Mark KAPLAN, Dmitry BABICH, Lior COHEN
-
Patent number: 10020941Abstract: Techniques related to virtual encryption patching are described. A security gateway includes multiple Transport Layer Security Implementations (TLSI) that can be used for creating secure communications channels to carry application-layer traffic between one or more clients and one or more server applications. In some embodiments, upon determining that one of the multiple TLSIs contains a security vulnerability, that TLSI can be disabled, leaving one or more others of the multiple TLSIs enabled and available to be used to carry traffic of new connections between the clients and server applications.Type: GrantFiled: November 17, 2015Date of Patent: July 10, 2018Assignee: Imperva, Inc.Inventors: Amichai Shulman, Itsik Mantin, Nadav Avital, Offir Zigelman, Oren Brezner, Dmitry Babich
-
Publication number: 20170093824Abstract: Techniques related to virtual encryption patching are described. A security gateway includes multiple Transport Layer Security Implementations (TLSI) that can be used for creating secure communications channels to carry application-layer traffic between one or more clients and one or more server applications. In some embodiments, upon determining that one of the multiple TLSIs contains a security vulnerability, that TLSI can be disabled, leaving one or more others of the multiple TLSIs enabled and available to be used to carry traffic of new connections between the clients and server applications.Type: ApplicationFiled: November 17, 2015Publication date: March 30, 2017Inventors: Amichai SHULMAN, Itsik MANTIN, Nadav AVITAL, Offir ZIGELMAN, Oren BREZNER, Dmitry BABICH
-
Patent number: 9553892Abstract: According to one embodiment, a transparent security gateway is coupled between a client end station (CES) and a web application server (WAS). The security gateway monitors an encryption protocol handshake between the CES and the WAS to capture, using a provided private key of the WAS, a generated symmetric key to be used for an encryption layer connection. Using the captured symmetric key, the security gateway receives an encrypted connection record of the encryption layer connection, decrypts the encrypted connection record to yield a plaintext connection record, modifies the plaintext connection record, encrypts the modified plaintext connection record using the symmetric key, and transmits one or more packets carrying the encrypted modification plaintext connection record instead of the received encrypted connection record such that neither the CES or WAS is aware of the modification of the encrypted data.Type: GrantFiled: August 21, 2015Date of Patent: January 24, 2017Assignee: IMPERVA, INC.Inventors: Ido Kelson, Dmitry Babich
-
Patent number: 9456002Abstract: According to one embodiment, a transparent security gateway is coupled between a client end station (CES) and a web application server (WAS). The security gateway monitors an encryption protocol handshake between the CES and the WAS to capture, using a provided private key of the WAS, a generated symmetric key to be used for an encryption layer connection. Using the captured symmetric key, the security gateway receives an encrypted connection record of the encryption layer connection, decrypts the encrypted connection record to yield a plaintext connection record, modifies the plaintext connection record, encrypts the modified plaintext connection record using the symmetric key, and transmits one or more packets carrying the encrypted modification plaintext connection record instead of the received encrypted connection record such that neither the CES or WAS is aware of the modification of the encrypted data.Type: GrantFiled: August 21, 2015Date of Patent: September 27, 2016Assignee: Imperva, Inc.Inventors: Ido Kelson, Dmitry Babich
-
Publication number: 20150381656Abstract: According to one embodiment, a transparent security gateway is coupled between a client end station (CES) and a web application server (WAS). The security gateway monitors an encryption protocol handshake between the CES and the WAS to capture, using a provided private key of the WAS, a generated symmetric key to be used for an encryption layer connection. Using the captured symmetric key, the security gateway receives an encrypted connection record of the encryption layer connection, decrypts the encrypted connection record to yield a plaintext connection record, modifies the plaintext connection record, encrypts the modified plaintext connection record using the symmetric key, and transmits one or more packets carrying the encrypted modification plaintext connection record instead of the received encrypted connection record such that neither the CES or WAS is aware of the modification of the encrypted data.Type: ApplicationFiled: August 21, 2015Publication date: December 31, 2015Inventors: Ido KELSON, Dmitry BABICH
-
Publication number: 20150381657Abstract: According to one embodiment, a transparent security gateway is coupled between a client end station (CES) and a web application server (WAS). The security gateway monitors an encryption protocol handshake between the CES and the WAS to capture, using a provided private key of the WAS, a generated symmetric key to be used for an encryption layer connection. Using the captured symmetric key, the security gateway receives an encrypted connection record of the encryption layer connection, decrypts the encrypted connection record to yield a plaintext connection record, modifies the plaintext connection record, encrypts the modified plaintext connection record using the symmetric key, and transmits one or more packets carrying the encrypted modification plaintext connection record instead of the received encrypted connection record such that neither the CES or WAS is aware of the modification of the encrypted data.Type: ApplicationFiled: August 21, 2015Publication date: December 31, 2015Inventors: Ido KELSON, Dmitry BABICH
-
Patent number: 9148446Abstract: According to one embodiment, a transparent security gateway is coupled between a client end station (CES) and a web application server (WAS). The security gateway monitors an encryption protocol handshake between the CES and the WAS to capture, using a provided private key of the WAS, a generated symmetric key to be used for an encryption layer connection. Using the captured symmetric key, the security gateway receives an encrypted connection record of the encryption layer connection, decrypts the encrypted connection record to yield a plaintext connection record, modifies the plaintext connection record, encrypts the modified plaintext connection record using the symmetric key, and transmits one or more packets carrying the encrypted modification plaintext connection record instead of the received encrypted connection record such that neither the CES or WAS is aware of the modification of the encrypted data.Type: GrantFiled: November 15, 2013Date of Patent: September 29, 2015Assignee: IMPERVA, INC.Inventors: Ido Kelson, Dmitry Babich
-
Publication number: 20140337614Abstract: According to one embodiment, a transparent security gateway is coupled between a client end station (CES) and a web application server (WAS). The security gateway monitors an encryption protocol handshake between the CES and the WAS to capture, using a provided private key of the WAS, a generated symmetric key to be used for an encryption layer connection. Using the captured symmetric key, the security gateway receives an encrypted connection record of the encryption layer connection, decrypts the encrypted connection record to yield a plaintext connection record, modifies the plaintext connection record, encrypts the modified plaintext connection record using the symmetric key, and transmits one or more packets carrying the encrypted modification plaintext connection record instead of the received encrypted connection record such that neither the CES or WAS is aware of the modification of the encrypted data.Type: ApplicationFiled: November 15, 2013Publication date: November 13, 2014Applicant: Imperva, Inc.Inventors: Ido Kelson, Dmitry Babich