Patents by Inventor Dmitry Babich

Dmitry Babich has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20260189508
    Abstract: Systems, methods, and computer readable medium are disclosed for load balancing network traffic. Load balancing network traffic includes receiving at a particular server among a plurality of candidate servers, one of a plurality of probes sent from a client device to the plurality of candidate servers; interpreting, at the particular server, the received probe to recognize that the received probe is a precursor to a persistent connection between the particular server and the client device; determining that a prospective connection between the particular server and the client device would be sub-optimal; and transmitting a biased response from the particular server to the client device to discourage establishment of the persistent connection between the client device and the particular server.
    Type: Application
    Filed: October 24, 2025
    Publication date: July 2, 2026
    Applicant: CATO NETWORKS LTD
    Inventors: Mark KAPLAN, Aviram KATZENSTEIN, Dmitry BABICH, David GOLDBERGER, Eyal HEIMAN
  • Publication number: 20260186764
    Abstract: Systems, methods, and computer readable medium are disclosed for altering network connections during maintenance periods. Altering network connections during maintenance periods includes monitoring via a cloud service, a network of distributed servers and client devices, the monitoring including maintaining records of software upgrade schedules for the servers and existing tunnels between the client devices and the servers; receiving at the cloud service a request to upgrade software on a particular server; in response to the request, scheduling the software upgrade; accessing the records to identify an existing tunnel between a client device and the particular server; prior to the scheduled upgrade, accessing the records to identify an alternative server to which existing tunnel traffic can be directed during the upgrade; and following identification and prior to the scheduled upgrade, rerouting network traffic flow from the client to the alternative server to thereby avoid a communication blip.
    Type: Application
    Filed: October 31, 2025
    Publication date: July 2, 2026
    Applicant: CATO NETWORKS LTD
    Inventors: Aviram KATZENSTEIN, Dmitry Babich, David Goldberger, Eyal Heiman, Raz Ashkenazi
  • Publication number: 20260189611
    Abstract: Systems, methods, and computer readable medium are disclosed for real-time dynamic policy revisions.
    Type: Application
    Filed: October 31, 2025
    Publication date: July 2, 2026
    Applicant: CATO NETWORKS LTD
    Inventors: Eyal HEIMAN, Ofir AGASI, Mark KAPLAN, Elad MENAHEM, Rotem SHAMIR, Dmitry BABICH, Peter NOVIKOV, Avraham GRUDA, Noa BARON, Uri SIVAN
  • Publication number: 20260189981
    Abstract: Systems, methods, and computer-readable media are described for facilitating network synchronization within a network comprising multiple distributed server clusters connected to various edge devices. The synchronization process involves maintaining multiple copies of a routing table, which are distributed across the locations of the server clusters and edge devices. When a connectivity change occurs and is detected by at least one server in the distributed server clusters, this change is represented as a delta in the routing table. The delta is then distributed across the server clusters and edge devices to update and synchronize all copies of the routing table, ensuring consistency across the network.
    Type: Application
    Filed: October 24, 2025
    Publication date: July 2, 2026
    Applicant: CATO NETWORKS LTD.
    Inventors: Aviram KATZENSTEIN, Dmitry BABICH
  • Publication number: 20260189483
    Abstract: Systems, methods, and computer-readable media are described for facilitating network synchronization within a network comprising multiple distributed server clusters connected to various edge devices. The synchronization process involves maintaining multiple copies of a routing table, which are distributed across the locations of the server clusters and edge devices. When a connectivity change occurs and is detected by at least one server in the distributed server clusters, this change is represented as a delta in the routing table. The delta is then distributed across the server clusters and edge devices to update and synchronize all copies of the routing table, ensuring consistency across the network.
    Type: Application
    Filed: October 24, 2025
    Publication date: July 2, 2026
    Applicant: CATO NETWORKS LTD
    Inventors: Tomer DOITSHMAN, Rina BRUTER, Dolev MANASSEN, Aviv ABELSON, Rotem NAAR SHAMIR, Dmitry BABICH, Elad MENAHEM, Mark KAPLAN
  • Publication number: 20260189608
    Abstract: Systems, methods, and computer-readable media are described for facilitating network synchronization within a network comprising multiple distributed server clusters connected to various edge devices. The synchronization process involves maintaining multiple copies of a routing table, which are distributed across the locations of the server clusters and edge devices. When a connectivity change occurs and is detected by at least one server in the distributed server clusters, this change is represented as a delta in the routing table. The delta is then distributed across the server clusters and edge devices to update and synchronize all copies of the routing table, ensuring consistency across the network.
    Type: Application
    Filed: October 24, 2025
    Publication date: July 2, 2026
    Applicant: CATO NETWORKS LTD
    Inventors: Raz ASHKENAZI, Mark KAPLAN, Dmitry BABICH, Lior COHEN
  • Patent number: 10020941
    Abstract: Techniques related to virtual encryption patching are described. A security gateway includes multiple Transport Layer Security Implementations (TLSI) that can be used for creating secure communications channels to carry application-layer traffic between one or more clients and one or more server applications. In some embodiments, upon determining that one of the multiple TLSIs contains a security vulnerability, that TLSI can be disabled, leaving one or more others of the multiple TLSIs enabled and available to be used to carry traffic of new connections between the clients and server applications.
    Type: Grant
    Filed: November 17, 2015
    Date of Patent: July 10, 2018
    Assignee: Imperva, Inc.
    Inventors: Amichai Shulman, Itsik Mantin, Nadav Avital, Offir Zigelman, Oren Brezner, Dmitry Babich
  • Publication number: 20170093824
    Abstract: Techniques related to virtual encryption patching are described. A security gateway includes multiple Transport Layer Security Implementations (TLSI) that can be used for creating secure communications channels to carry application-layer traffic between one or more clients and one or more server applications. In some embodiments, upon determining that one of the multiple TLSIs contains a security vulnerability, that TLSI can be disabled, leaving one or more others of the multiple TLSIs enabled and available to be used to carry traffic of new connections between the clients and server applications.
    Type: Application
    Filed: November 17, 2015
    Publication date: March 30, 2017
    Inventors: Amichai SHULMAN, Itsik MANTIN, Nadav AVITAL, Offir ZIGELMAN, Oren BREZNER, Dmitry BABICH
  • Patent number: 9553892
    Abstract: According to one embodiment, a transparent security gateway is coupled between a client end station (CES) and a web application server (WAS). The security gateway monitors an encryption protocol handshake between the CES and the WAS to capture, using a provided private key of the WAS, a generated symmetric key to be used for an encryption layer connection. Using the captured symmetric key, the security gateway receives an encrypted connection record of the encryption layer connection, decrypts the encrypted connection record to yield a plaintext connection record, modifies the plaintext connection record, encrypts the modified plaintext connection record using the symmetric key, and transmits one or more packets carrying the encrypted modification plaintext connection record instead of the received encrypted connection record such that neither the CES or WAS is aware of the modification of the encrypted data.
    Type: Grant
    Filed: August 21, 2015
    Date of Patent: January 24, 2017
    Assignee: IMPERVA, INC.
    Inventors: Ido Kelson, Dmitry Babich
  • Patent number: 9456002
    Abstract: According to one embodiment, a transparent security gateway is coupled between a client end station (CES) and a web application server (WAS). The security gateway monitors an encryption protocol handshake between the CES and the WAS to capture, using a provided private key of the WAS, a generated symmetric key to be used for an encryption layer connection. Using the captured symmetric key, the security gateway receives an encrypted connection record of the encryption layer connection, decrypts the encrypted connection record to yield a plaintext connection record, modifies the plaintext connection record, encrypts the modified plaintext connection record using the symmetric key, and transmits one or more packets carrying the encrypted modification plaintext connection record instead of the received encrypted connection record such that neither the CES or WAS is aware of the modification of the encrypted data.
    Type: Grant
    Filed: August 21, 2015
    Date of Patent: September 27, 2016
    Assignee: Imperva, Inc.
    Inventors: Ido Kelson, Dmitry Babich
  • Publication number: 20150381656
    Abstract: According to one embodiment, a transparent security gateway is coupled between a client end station (CES) and a web application server (WAS). The security gateway monitors an encryption protocol handshake between the CES and the WAS to capture, using a provided private key of the WAS, a generated symmetric key to be used for an encryption layer connection. Using the captured symmetric key, the security gateway receives an encrypted connection record of the encryption layer connection, decrypts the encrypted connection record to yield a plaintext connection record, modifies the plaintext connection record, encrypts the modified plaintext connection record using the symmetric key, and transmits one or more packets carrying the encrypted modification plaintext connection record instead of the received encrypted connection record such that neither the CES or WAS is aware of the modification of the encrypted data.
    Type: Application
    Filed: August 21, 2015
    Publication date: December 31, 2015
    Inventors: Ido KELSON, Dmitry BABICH
  • Publication number: 20150381657
    Abstract: According to one embodiment, a transparent security gateway is coupled between a client end station (CES) and a web application server (WAS). The security gateway monitors an encryption protocol handshake between the CES and the WAS to capture, using a provided private key of the WAS, a generated symmetric key to be used for an encryption layer connection. Using the captured symmetric key, the security gateway receives an encrypted connection record of the encryption layer connection, decrypts the encrypted connection record to yield a plaintext connection record, modifies the plaintext connection record, encrypts the modified plaintext connection record using the symmetric key, and transmits one or more packets carrying the encrypted modification plaintext connection record instead of the received encrypted connection record such that neither the CES or WAS is aware of the modification of the encrypted data.
    Type: Application
    Filed: August 21, 2015
    Publication date: December 31, 2015
    Inventors: Ido KELSON, Dmitry BABICH
  • Patent number: 9148446
    Abstract: According to one embodiment, a transparent security gateway is coupled between a client end station (CES) and a web application server (WAS). The security gateway monitors an encryption protocol handshake between the CES and the WAS to capture, using a provided private key of the WAS, a generated symmetric key to be used for an encryption layer connection. Using the captured symmetric key, the security gateway receives an encrypted connection record of the encryption layer connection, decrypts the encrypted connection record to yield a plaintext connection record, modifies the plaintext connection record, encrypts the modified plaintext connection record using the symmetric key, and transmits one or more packets carrying the encrypted modification plaintext connection record instead of the received encrypted connection record such that neither the CES or WAS is aware of the modification of the encrypted data.
    Type: Grant
    Filed: November 15, 2013
    Date of Patent: September 29, 2015
    Assignee: IMPERVA, INC.
    Inventors: Ido Kelson, Dmitry Babich
  • Publication number: 20140337614
    Abstract: According to one embodiment, a transparent security gateway is coupled between a client end station (CES) and a web application server (WAS). The security gateway monitors an encryption protocol handshake between the CES and the WAS to capture, using a provided private key of the WAS, a generated symmetric key to be used for an encryption layer connection. Using the captured symmetric key, the security gateway receives an encrypted connection record of the encryption layer connection, decrypts the encrypted connection record to yield a plaintext connection record, modifies the plaintext connection record, encrypts the modified plaintext connection record using the symmetric key, and transmits one or more packets carrying the encrypted modification plaintext connection record instead of the received encrypted connection record such that neither the CES or WAS is aware of the modification of the encrypted data.
    Type: Application
    Filed: November 15, 2013
    Publication date: November 13, 2014
    Applicant: Imperva, Inc.
    Inventors: Ido Kelson, Dmitry Babich