Patents by Inventor Elik Levin

Elik Levin has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 12688290
    Abstract: Techniques for detecting security issues in a storage array are disclosed. A service receives, from a host, an indication of compromise (IOC) reflecting that the host is suspected of being compromised. In response, the service refrains from turning on inline IO checking. In lieu of turning on the inline IO checking, the service triggers monitoring of previous snapshots stored on a specific storage device in the array to detect a trail of a possible attack. The service provides a notification to a centralized security system of the possible attack on the specific storage device. The notification is structured to operate as a triggering mechanism to cause the centralized security system to identify a second storage array that is in communication with the host and to further cause the centralized security system to instruct the second storage array to search for a second possible attack on the second storage array.
    Type: Grant
    Filed: April 2, 2024
    Date of Patent: July 21, 2026
    Assignee: Dell Products L.P.
    Inventors: Elik Levin, Arieh Don
  • Patent number: 12596802
    Abstract: In at least one embodiment, processing can include: detecting a first unexpected change to a first characteristic for a first storage object (SO); detecting no unexpected change to the first characteristic for a second SO; and responsive to said detecting the first unexpected change, performing first processing including: detecting a second unexpected change to a second characteristic for the first SO; creating an indication of compromise (IOC) including a signature characterizing behavior of suspected malware activity impacting the first SO, the signature including the first and second unexpected changes; detecting a third unexpected change to the second characteristic with respect to the second SO; determining, in accordance with criteria, that unexpected changes in I/O activity of the second SO match the IOC, wherein the unexpected changes include the third unexpected change; and responsive to determining the unexpected changes match the IOC, determining suspected malware activity impacting the second SO.
    Type: Grant
    Filed: March 29, 2024
    Date of Patent: April 7, 2026
    Assignee: Dell Products L.P.
    Inventors: Matthew Long, Elik Levin, Arieh Don
  • Publication number: 20250378159
    Abstract: A detection engine for detecting threats to a computing system is disclosed. The detection engine includes an interceptor that is positioned in a data path and configured to intercept IOs. The interceptor transmits a data stream, which may include data and/or metadata or the intercepted IOs, to a detector. The detector perform a detection analysis. When a threat is detected, a response may be initiated. The interceptor is configured to perform the response.
    Type: Application
    Filed: June 6, 2024
    Publication date: December 11, 2025
    Inventors: Elik Levin, Jehuda Shemer, Gaurav Chawla, Arthur Lent
  • Publication number: 20250378163
    Abstract: A detection engine for detecting threats to a computing system is disclosed. The detection engine includes a detector cluster and one or more interceptors. The interceptors are positioned at various locations in a data path of a computing system and configured to intercept IOs. The IOs, or portions thereof, are analyzed for threats by the detectors. Detectors in the detector cluster are each associated with at least one interceptor and each detector receives data streams from connected interceptors. When a threat is detected by a detector, a response may be initiated. The response may include sharing knowledge about the threat with other detectors in the detector cluster. In addition, interceptors may be redirected when a detector fails and detector workloads, such as number of connected interceptors, may be rebalanced.
    Type: Application
    Filed: June 6, 2024
    Publication date: December 11, 2025
    Inventors: Elik Levin, Jehuda Shemer, Gaurav Chawla, Arthur Lent
  • Publication number: 20250377960
    Abstract: A detection engine for handling communication errors while performing threat detection in a computing system is disclosed. The detection engine includes an interceptor that is positioned in a data path and configured to intercept IOs. The interceptor transmits a data stream, which may include data and/or metadata or the intercepted IOs, to a detector. The detector perform a detection analysis. When a threat is detected, a response may be initiated. When a communication error is present with respect to the detection engine, the interceptor may perform error handling operations. The error handling operations may store tracking data that allow the detector to catch-up with respect to the detection analysis when the communication error is resolved.
    Type: Application
    Filed: June 6, 2024
    Publication date: December 11, 2025
    Inventors: Elik Levin, Jehuda Shemer, Gaurav Chawla, Arthur Lent
  • Publication number: 20250307400
    Abstract: Techniques for detecting security issues in a storage array are disclosed. A service receives, from a host, an indication of compromise (IOC) reflecting that the host is suspected of being compromised. In response, the service refrains from turning on inline IO checking. In lieu of turning on the inline IO checking, the service triggers monitoring of previous snapshots stored on a specific storage device in the array to detect a trail of a possible attack. The service provides a notification to a centralized security system of the possible attack on the specific storage device. The notification is structured to operate as a triggering mechanism to cause the centralized security system to identify a second storage array that is in communication with the host and to further cause the centralized security system to instruct the second storage array to search for a second possible attack on the second storage array.
    Type: Application
    Filed: April 2, 2024
    Publication date: October 2, 2025
    Inventors: Elik Levin, Arieh Don
  • Publication number: 20250307395
    Abstract: In at least one embodiment, processing can include: detecting a first unexpected change to a first characteristic for a first storage object (SO); detecting no unexpected change to the first characteristic for a second SO; and responsive to said detecting the first unexpected change, performing first processing including: detecting a second unexpected change to a second characteristic for the first SO; creating an indication of compromise (IOC) including a signature characterizing behavior of suspected malware activity impacting the first SO, the signature including the first and second unexpected changes; detecting a third unexpected change to the second characteristic with respect to the second SO; determining, in accordance with criteria, that unexpected changes in I/O activity of the second SO match the IOC, wherein the unexpected changes include the third unexpected change; and responsive to determining the unexpected changes match the IOC, determining suspected malware activity impacting the second SO.
    Type: Application
    Filed: March 29, 2024
    Publication date: October 2, 2025
    Applicant: Dell Products L.P.
    Inventors: Matthew Long, Elik Levin, Arieh Don
  • Patent number: 12299118
    Abstract: An apparatus comprises at least one processing device configured to implement a multi-path layer in a host device, wherein the multi-path layer controls delivery of input-output (IO) operations from the host device to a storage system over selected ones of a plurality of paths through a network. The multi-path layer is configured, for each of at least a subset of the IO operations, to store at least a process identifier, a user identifier and an access type for the IO operation. The multi-path layer is further configured to perform analytics on the stored process identifiers, user identifiers and access types to detect an access pattern, and responsive to the detected access pattern having one or more designated characteristics associated with malware, to generate an alert. The alert may be generated by inserting security alert indicators into respective ones of the IO operations, for extraction therefrom by the storage system.
    Type: Grant
    Filed: April 29, 2022
    Date of Patent: May 13, 2025
    Assignee: Dell Products L.P.
    Inventors: Sanjib Mallick, Arieh Don, Elik Levin, Kundan Kumar, Gaurav Singh
  • Patent number: 12277107
    Abstract: Methods and systems for managing database data stored in a storage array and on behalf of a data processing system hosting a database application are disclosed. The database data may be managed by checking for changes in records of the database data. A record of the records may be checked for the changes by comparing a first checksum, hash, and/or cryptographic string from the record to a second first checksum, hash, and/or cryptographic string computed by a data processing system. If the first checksum matches the second checksum, then the record may be validated. Validating a record of the records by checking the changes in the records, rather than all the records, of the database data may permit computing resources to be available for use in other computer implemented services.
    Type: Grant
    Filed: April 26, 2024
    Date of Patent: April 15, 2025
    Assignee: Dell Products L.P.
    Inventors: Elik Levin, Arieh Don
  • Publication number: 20230351013
    Abstract: An apparatus comprises at least one processing device configured to implement a multi-path layer in a host device, wherein the multi-path layer controls delivery of input-output (IO) operations from the host device to a storage system over selected ones of a plurality of paths through a network. The multi-path layer is configured, for each of at least a subset of the IO operations, to store at least a process identifier, a user identifier and an access type for the IO operation. The multi-path layer is further configured to perform analytics on the stored process identifiers, user identifiers and access types to detect an access pattern, and responsive to the detected access pattern having one or more designated characteristics associated with malware, to generate an alert. The alert may be generated by inserting security alert indicators into respective ones of the IO operations, for extraction therefrom by the storage system.
    Type: Application
    Filed: April 29, 2022
    Publication date: November 2, 2023
    Inventors: Sanjib Mallick, Arieh Don, Elik Levin, Kundan Kumar, Gaurav Singh
  • Patent number: 10587642
    Abstract: At least one security incident indicative of at least one security event that may impact or has impacted one or more assets associated with an organization is obtained. The at least one security incident is automatically ranked based on one or more of: (i) one or more rankings associated with one or more security incidents that precede the at least one security incident in time; and (ii) one or more values attributed to the one or more assets of the organization. The ranking of the at least one security incident is presented to an entity to make an assessment of the security event.
    Type: Grant
    Filed: July 26, 2017
    Date of Patent: March 10, 2020
    Assignee: EMC IP Holding Company LLC
    Inventors: Or Herman-Saffar, Amihai Savir, Stephen Todd, Elik Levin
  • Patent number: 10586046
    Abstract: At least one security feed indicative of at least one security event that may impact or has impacted one or more assets associated with an organization is obtained. The at least one security feed is automatically classified as being relevant or not relevant. The at least one security feed is automatically ranked in response to the at least one security feed being classified as relevant. The ranking of the at least one security feed is presented to an entity to make an assessment of the security event.
    Type: Grant
    Filed: July 26, 2017
    Date of Patent: March 10, 2020
    Assignee: EMC IP Holding Company LLC
    Inventors: Or Herman-Saffar, Amihai Savir, Stephen Todd, Elik Levin