Patents by Inventor Fady Copty

Fady Copty has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 12682229
    Abstract: In an approach for policy security shifting left of infrastructure as code compliance, a processor trains a neural network model to classify a code per policy and provide a policy vector score for the code associated with one or more policies. A processor enables the neural network model to scan and score a new code during a continuous integration and continuous deployment pipeline. A processor outputs a scanned score of the new code to a user. A processor retrains the neural network model by capturing a continuous integration and continuous deployment change and run-time compliance posture that occurs as a response by the user.
    Type: Grant
    Filed: March 29, 2021
    Date of Patent: July 14, 2026
    Assignee: International Business Machines Corporation
    Inventor: Fady Copty
  • Publication number: 20260189592
    Abstract: Provided are a computer implemented method, system, and computer program product for determining vulnerability of computational resources to attack vectors. A potential attack vector is detected that is directed to a targeted resource of the computational resources that matches a known attack vector of a plurality of known attack vectors. Attributes of attack vectors directed to the targeted resource are processed, including the attributes of the known attack vector, to generate a vulnerability score for the targeted resource indicating a likelihood the targeted resource is exposed to a malicious attack. A lower vulnerability score indicates the targeted resource is less susceptible to the malicious attack than a higher vulnerability score. An alert is generated in response to determining that the generated vulnerability score indicates an increased vulnerability to the malicious attack.
    Type: Application
    Filed: January 2, 2025
    Publication date: July 2, 2026
    Inventors: OMRI SOCEANU, FADY COPTY, DAVID HADAS
  • Publication number: 20260187551
    Abstract: A method disclosed herein facilitates autonomous learning of an ownership data structure and use of the ownership data structure to assign tasks in a response workflow. The method includes determining a sequence of tasks in the response workflow and accessing a security graph to retrieve resource information pertaining to a target resource of a select task in the sequence of tasks. The method further includes using the resource information to generate a roll description that identifies one or more attributes of a candidate qualified to perform the select task and selecting a first individual from the ownership data structure as a candidate for ownership of the select task based on the roll description and descriptions of employment rolls stored within an ownership data structure of the enterprise. The method still further provides for creating a ticket in a ticketing system that assigns the select task to the first individual.
    Type: Application
    Filed: December 26, 2024
    Publication date: July 2, 2026
    Inventors: Fady COPTY, Yoav YASSOUR, Roee OZ, Tamer SALMAN, Tomer TELLER
  • Patent number: 12651153
    Abstract: A method for detecting security vulnerabilities, comprising: generating a corpus of input samples each labeled to indicate a threat level when executed by an input processing code; training a neural network (NN) using the plurality of input samples to classify inputs according to a plurality of labels of the plurality of input samples; for each input sample: iteratively altering the input sample to correspond to a process of gradient change of the NN, until the NN classifies the altered input sample to a different label than a respective label of the input sample; assigning the different label to the altered input sample; using the plurality of relabeled altered input samples to further train the NN and augment the corpus of input samples.
    Type: Grant
    Filed: October 18, 2018
    Date of Patent: June 9, 2026
    Assignee: International Business Machines Corporation
    Inventors: Fady Copty, Dov Murik
  • Publication number: 20260122109
    Abstract: This disclosure describes a proactive deployment impact system that detects and addresses the security impact of candidate code-based infrastructure changes before they are deployed in a production environment within a cloud computing system. The proactive deployment impact system implements a lightweight preemptive security framework, based on runtime resource information, to determine whether a requested candidate code-based infrastructure change would introduce new security risks, attack patterns, or breach vulnerabilities. Furthermore, the proactive deployment impact system can actively block the deployment of negatively impacting candidate changes, report potential security breaches, and/or automatically modify the candidate changes to eliminate security vulnerabilities.
    Type: Application
    Filed: October 29, 2024
    Publication date: April 30, 2026
    Inventors: Fady COPTY, Aviv David ELDAN, Asaf NAKASH, Yoav SAROYA
  • Publication number: 20260100959
    Abstract: Techniques are described herein that are capable of performing a security action based on a communication-based analysis. A security event, which is triggered by an operation performed by a user in an organization, is detected. A security analysis result is generated by determining whether a communication history of the user includes (1) a communication from the user that initiates an interaction with another user in the organization and/or a communication that is addressed specifically to the user from another user in the organization, (2) a communication from the user that references the operation, and/or (3) a communication that provides an explanation of a purpose of the operation that satisfies an explanation criterion. In response to the security event, a security action is performed with regard to the operation as a result of the security analysis result satisfying a security criterion.
    Type: Application
    Filed: October 7, 2024
    Publication date: April 9, 2026
    Inventors: Doron BAR SHALOM, Andrey KARPOVSKY, Fady COPTY
  • Publication number: 20260099592
    Abstract: Techniques are described herein that are capable of performing a security action based on an AI-determined intent and/or impact of a resource in an enterprise. A security alert regarding an identified resource of an enterprise is received. Intents of subsets of information regarding a software application utilized by the enterprise are determined using an AI model. The intents are mapped to subsets of resources in the enterprise and/or the AI model is used to determine impacts of the subsets of the resources on the enterprise. In response to the security alert, a security action is performed with regard to the identified resource as a result of an intent and/or impact associated with the identified resource satisfying an action criterion associated with the security action.
    Type: Application
    Filed: October 3, 2024
    Publication date: April 9, 2026
    Inventors: Amir PIROGOVSKY, Doron BAR SHALOM, Fady COPTY, Amir Berko SCHWARTZ
  • Publication number: 20260081940
    Abstract: Systems, methods, and techniques are directed to detecting potential anomalous activity based on changes in a security graph. In an example, a security system receives a first snapshot of a graph representative of a tenant account of a network-based system corresponding to a first timestamp. The security system receives a second snapshot of the graph corresponding to a second timestamp. The security system determines a first change in the graph based on the first and second snapshots and a second change related to the first change. The security system detects a potential anomaly based on the first and second changes. Responsive to detecting a potential anomaly, the security system causes a mitigation step to be performed with respect to the tenant account. In a further example, the security system determines relationships between a sequence of changes satisfies a cumulative anomaly criterion.
    Type: Application
    Filed: September 19, 2024
    Publication date: March 19, 2026
    Inventors: Moshe ISRAEL, Andrey KARPOVSKY, Fady COPTY
  • Publication number: 20260050427
    Abstract: According to examples, an apparatus includes a processor that may obtain and parse a pipeline code to determine how variables of the pipeline code relate to each other, and replace the variables in the parsed pipeline code with values to which the variables respectively represent, in which the values correspond to pipeline run sources and pipeline run targets of API calls. The processor may also identify how the pipeline run targets interact with the pipeline run sources of the API calls and build a dependency graph that maps the pipeline run sources with the pipeline run targets. Runtime resources may thus be mapped to source code in a pipeline run to provide visibility into actions carried out by the pipeline. This visibility may be used to determine whether there are security vulnerabilities in the pipeline run sources and/or targets such that the vulnerabilities may be addressed/overcome.
    Type: Application
    Filed: October 27, 2025
    Publication date: February 19, 2026
    Inventor: Fady COPTY
  • Patent number: 12554839
    Abstract: Methods, systems, and computer storage media for providing data security posture management using an application discovery engine in a security management system. Application discovery supports identifying and mapping various applications within a computing environment. In particular, application discovery can be provided as part of security management operations to assess security posture of applications, identify vulnerabilities, and ensure compliance with regulations. In operation, application discovery data associated with a plurality computing resources of a computing environment is accessed. An annotated application discovery graph comprising a plurality of entities that represent the plurality of computing resources is generated. The annotated application discovery graph is deployed to support generating security postures for computing environments. A request is received for a security posture of the computing environment.
    Type: Grant
    Filed: June 7, 2023
    Date of Patent: February 17, 2026
    Assignee: Microsoft Technology Licensing, LLC
    Inventors: Shay Chriba Sakazi, Fady Copty, Tamer Salman, Ofir Monza
  • Patent number: 12530460
    Abstract: Techniques are described herein that are capable of providing automated governance policy-based security for a cloud native application. Recently unused security misconfigurations of a cloud native application are identified. A first configuration change that resolves a first recently unused security misconfiguration is automatically implemented as a result of the first configuration change being capable of reducing productivity of a user and having a likelihood of reducing security of the cloud native application that is greater than or equal to a likelihood threshold.
    Type: Grant
    Filed: May 31, 2024
    Date of Patent: January 20, 2026
    Assignee: Microsoft Technology Licensing, LLC
    Inventors: Tamer Salman, Fady Copty
  • Publication number: 20260006039
    Abstract: The disclosed techniques automatically identify cyber-security attacks and predict attack next steps. Descriptions of previously observed cyber-attack campaigns are decomposed into attack campaign steps. Real-time security incident signals are generated by cybersecurity software. Attack campaigns are identified by mapping attack campaign steps to security incident signals. Custom-generated telemetry queries are executed to determine if a missing attack campaign step occurred. A machine learning model generates embeddings for attack campaign steps, security incident signals, and telemetry query responses. A security incident signal or a telemetry query response matches an attack campaign step when their embeddings are within a defined distance. A security alert may be raised when most or all of the attack campaign steps of a particular attack campaign are matched. Attack campaign steps that are not matched to security incident signals or telemetry query results are predicted as attack next steps.
    Type: Application
    Filed: June 26, 2024
    Publication date: January 1, 2026
    Inventors: Andrey KARPOVSKY, Tamer SALMAN, Moshe ISRAEL, Fady COPTY
  • Publication number: 20250371157
    Abstract: Techniques are described herein that are capable of providing automated governance policy-based security for a cloud native application. Recently unused security misconfigurations of a cloud native application are identified. A first configuration change that resolves a first recently unused security misconfiguration is automatically implemented as a result of the first configuration change being capable of reducing productivity of a user and having a likelihood of reducing security of the cloud native application that is greater than or equal to a likelihood threshold.
    Type: Application
    Filed: May 31, 2024
    Publication date: December 4, 2025
    Inventors: Tamer SALMAN, Fady COPTY
  • Patent number: 12481487
    Abstract: According to examples, an apparatus includes a processor that may obtain and parse a pipeline code to determine how variables of the pipeline code relate to each other, and replace the variables in the parsed pipeline code with values to which the variables respectively represent, in which the values correspond to pipeline run sources and pipeline run targets of API calls. The processor may also identify how the pipeline run targets interact with the pipeline run sources of the API calls and build a dependency graph that maps the pipeline run sources with the pipeline run targets. Runtime resources may thus be mapped to source code in a pipeline run to provide visibility into actions carried out by the pipeline. This visibility may be used to determine whether there are security vulnerabilities in the pipeline run sources and/or targets such that the vulnerabilities may be addressed/overcome.
    Type: Grant
    Filed: May 11, 2023
    Date of Patent: November 25, 2025
    Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
    Inventor: Fady Copty
  • Publication number: 20250138805
    Abstract: A distributed computing system may include a code repository server configured to store code, a code deployment server configured to receive a deployment of the code, and a development and operations (DevOps) server configured to construct a pipeline between the code repository server and the code deployment server. The DevOps server may be configured to execute a source code management program to receive a request for information regarding a target resource that has been deployed using the pipeline, generate a permissions model for the target resource, the permissions model including one or more permissions, each permission authorizing a managed identity to execute an action related to the target resource, determine a permissions usage history of the permissions contained in the permissions model, filter the permissions model based on the permissions usage history, and generate a list of events determined to have occurred as the filtered permissions model.
    Type: Application
    Filed: November 1, 2023
    Publication date: May 1, 2025
    Applicant: Microsoft Technology Licensing, LLC
    Inventors: Fady COPTY, Moshe ISRAEL, David TRIGANO, Lara Nicole GOLDSTEIN
  • Publication number: 20240411867
    Abstract: Methods, systems, and computer storage media for providing data security posture management using an application discovery engine in a security management system. Application discovery supports identifying and mapping various applications within a computing environment. In particular, application discovery can be provided as part of security management operations to assess security posture of applications, identify vulnerabilities, and ensure compliance with regulations. In operation, application discovery data associated with a plurality computing resources of a computing environment is accessed. An annotated application discovery graph comprising a plurality of entities that represent the plurality of computing resources is generated. The annotated application discovery graph is deployed to support generating security postures for computing environments. A request is received for a security posture of the computing environment.
    Type: Application
    Filed: June 7, 2023
    Publication date: December 12, 2024
    Inventors: Shay Chriba SAKAZI, Fady Copty, Tamer SALMAN, Ofir MONZA
  • Publication number: 20240378037
    Abstract: According to examples, an apparatus includes a processor that may obtain and parse a pipeline code to determine how variables of the pipeline code relate to each other, and replace the variables in the parsed pipeline code with values to which the variables respectively represent, in which the values correspond to pipeline run sources and pipeline run targets of API calls. The processor may also identify how the pipeline run targets interact with the pipeline run sources of the API calls and build a dependency graph that maps the pipeline run sources with the pipeline run targets. Runtime resources may thus be mapped to source code in a pipeline run to provide visibility into actions carried out by the pipeline. This visibility may be used to determine whether there are security vulnerabilities in the pipeline run sources and/or targets such that the vulnerabilities may be addressed/overcome.
    Type: Application
    Filed: May 11, 2023
    Publication date: November 14, 2024
    Applicant: Microsoft Technology Licensing, LLC
    Inventor: Fady COPTY
  • Patent number: 12132751
    Abstract: An approach to predicting the outcome of a computer security response. The approach can analyze an unlabeled set of network data and based on the analysis, create a language model of the network. The approach can process the language model to predict a reduction factor associated with network availability. The approach can further process the language model and a malicious sequence to predict an effectiveness factor associated with blocking the malicious sequence. The approach can output bot the reduction factor and the effectiveness factor to a network administrator for determining the applicability of the computer security response.
    Type: Grant
    Filed: September 25, 2023
    Date of Patent: October 29, 2024
    Assignee: International Business Machines Corporation
    Inventor: Fady Copty
  • Patent number: 11947444
    Abstract: Embodiments may provide techniques that may provide more accurate and actionable alerts by cloud workload security systems so as to improve overall cloud workload security. For example, in an embodiment, a method may be implemented in a computer system comprising a processor, memory accessible by the processor, and computer program instructions stored in the memory and executable by the processor, and the method may comprise generating performance and security information relating to a software system during development of the software system, generating performance and security information relating to the software system during deployed operation of the software system, matching the performance and security information generated during development of the software system with the performance and security information generated during deployed operation of the software system to determine performance and security alerts to escalate, and reporting the escalated performance and security alerts.
    Type: Grant
    Filed: November 6, 2020
    Date of Patent: April 2, 2024
    Assignee: International Business Machines Corporation
    Inventors: Fady Copty, Omri Soceanu, Gilad Ezov, Ronen Levy
  • Publication number: 20240015174
    Abstract: An approach to predicting the outcome of a computer security response. The approach can analyze an unlabeled set of network data and based on the analysis, create a language model of the network. The approach can process the language model to predict a reduction factor associated with network availability. The approach can further process the language model and a malicious sequence to predict an effectiveness factor associated with blocking the malicious sequence. The approach can output bot the reduction factor and the effectiveness factor to a network administrator for determining the applicability of the computer security response.
    Type: Application
    Filed: September 25, 2023
    Publication date: January 11, 2024
    Inventor: Fady Copty