Patents by Inventor Gil Barash
Gil Barash has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12694136Abstract: In some examples, a system computes read burst indicators of read input/output (I/O) bursts to a storage system at respective time points, and computes encryption burst indicators of encryption I/O bursts at the respective time points. The system calculates a score based on the read burst indicators, the encryption burst indicators, and a distance factor that is based on a time distance between when a burst read I/O burst of the read I/O bursts occurred and when an encryption I/O burst of the encryption I/O bursts occurred. The system determines whether unauthorized access of a computing environment is occurring based on the score.Type: GrantFiled: October 28, 2024Date of Patent: July 28, 2026Assignee: Hewlett Packard Enterprise Development LPInventors: Omer Uretzky, Gil Barash
-
Patent number: 12663936Abstract: In some examples, a data protection system replicates write input/output (I/O) operations to entries of a journal stored in a storage system, and associates timers with the entries of the journal to provide timer-controlled immutability of the entries of the journal. Based on a first timer associated with a first entry of the entries of the journal indicating that a specified time duration has elapsed, the data protection system applies a first write I/O operation of the first entry to a backup data store that contains a copy of at least a portion of data in a primary data store. Prior to the first timer indicating that the specified time duration has elapsed, the data protection system prevents any modification of a storage location containing the first entry in the storage system.Type: GrantFiled: October 10, 2024Date of Patent: June 23, 2026Assignee: Hewlett Packard Enterprise Development LPInventors: Omer Uretzky, Gil Barash
-
Patent number: 12663962Abstract: An example includes receiving a read request specifying a target range and a target checkpoint, and executing a first query to retrieve a first entry of a metadata table. The first entry is a most recent entry of those entries that are older than the target checkpoint and record write ranges overlapping the target range. The example also includes, if the write range in the first entry does not cover all of the target range, determining a remaining portion of the target range that excludes the write range in the first entry. The example also includes executing a second query to retrieve a second entry of the metadata table, where the second entry is a most recent record in a second subset of entries that are older that the target checkpoint and record write ranges overlapping the remaining portion of the target location range.Type: GrantFiled: October 21, 2024Date of Patent: June 23, 2026Assignee: Hewlett Packard Enterprise Development LPInventors: Gil Barash, Maya Leshem, Shlomi Apel, Asaf Kariv
-
Patent number: 12632348Abstract: A a system may replicate a write event to a journal database, the write event involving a change of a source database including data points arranged in a multidimensional space. The replication of the write event may add a journal data point to the journal database. The journal data point may include write data of the write event and metadata indicating a write operation associated with the write data. Based on receipt of a recovery query associated with recovering data of the source database, the system may obtain, according to a filter in the recovery query, a first result from the journal database and a second result from the backup database. The system may merge the first result and the second result to produce a recovery result in response to the recovery query.Type: GrantFiled: August 29, 2024Date of Patent: May 19, 2026Assignee: Hewlett Packard Enterprise Development LPInventors: Omer Uretzky, Gil Barash
-
Publication number: 20260133880Abstract: A method and system for replicating data change operations in a virtualized environment is provided. A data change filter and a data change driver in a hypervisor intercept data change operations from a virtual machine. A replication processing service receives a first stream of data change operations from the data change driver and a second stream from the data change filter. The service identifies a matching data change operation in both streams, replicates operations from the first stream up to a transition point, and then replicates operations from the second stream starting from the transition point. The transition point is pre-defined with respect to the matching data change operation. This approach enables seamless migration between driver-based and filter-based replication methods while maintaining data consistency and continuity.Type: ApplicationFiled: November 11, 2024Publication date: May 14, 2026Inventors: Omer Uretzky, Gil Barash
-
Publication number: 20260133817Abstract: A method and system for replicating data change operations in a virtualized environment is provided. A data change filter in a hypervisor of a virtualization host intercepts data change operations from a virtual machine. A network connection is established between the data change filter and a replication processing service executing on a separate replication host. The replication processing service receives the data change operations from the data change filter over the network connection and replicates the data change operations to a backup site.Type: ApplicationFiled: November 11, 2024Publication date: May 14, 2026Inventors: Omer Uretzky, Gil Barash, Roi Romy
-
Publication number: 20260135716Abstract: A method and system for configuring a data change filter in a virtualized environment are provided. A data change filter is installed in a hypervisor of a virtualization host, where the hypervisor executes a virtual machine. The data change filter intercepts data change operations from the virtual machine. The hypervisor includes a certificate management service that stores a private certificate for the data change filter and a public certificate for a replication processing service. The data change filter retrieves the certificates from the certificate management service, establishes an authenticated network connection with the replication processing service using the certificates, and sends the intercepted data change operations to the replication processing service over the authenticated connection. The system enables secure replication of data changes in virtualized environments.Type: ApplicationFiled: November 11, 2024Publication date: May 14, 2026Inventors: Omer Uretzky, Gil Barash, Bar-Hai Asulin, Roi Romy
-
Publication number: 20260119680Abstract: In some examples, a system computes read burst indicators of read input/output (I/O) bursts to a storage system at respective time points, and computes encryption burst indicators of encryption I/O bursts at the respective time points. The system calculates a score based on the read burst indicators, the encryption burst indicators, and a distance factor that is based on a time distance between when a burst read I/O burst of the read I/O bursts occurred and when an encryption I/O burst of the encryption I/O bursts occurred. The system determines whether unauthorized access of a computing environment is occurring based on the score.Type: ApplicationFiled: October 28, 2024Publication date: April 30, 2026Inventors: Omer Uretzky, Gil Barash
-
Publication number: 20260111172Abstract: An example includes receiving a read request specifying a target range and a target checkpoint, and executing a first query to retrieve a first entry of a metadata table. The first entry is a most recent entry of those entries that are older than the target checkpoint and record write ranges overlapping the target range. The example also includes, if the write range in the first entry does not cover all of the target range, determining a remaining portion of the target range that excludes the write range in the first entry. The example also includes executing a second query to retrieve a second entry of the metadata table, where the second entry is a most recent record in a second subset of entries that are older that the target checkpoint and record write ranges overlapping the remaining portion of the target location range.Type: ApplicationFiled: October 21, 2024Publication date: April 23, 2026Inventors: Gil Barash, Maya Leshem, Shlomi Apel, Asaf Kariv
-
Publication number: 20260105151Abstract: In some examples, a system identifies a first block input/output (I/O) operation relating to writing metadata for a data object, the metadata of the first block I/O operation comprising first object type information. The system generates, based on a header of a second block I/O operation relating to writing object content to a target data object, second object type information relating to an object type of the target data object. The system compares the first object type information in the metadata of the first block I/O operation to the second object type information. Based on the comparing, the system determines whether an anomaly relating to data has occurred.Type: ApplicationFiled: October 15, 2024Publication date: April 16, 2026Inventors: Gil Barash, Tal Aloni, Omer Uretzky
-
Publication number: 20260104813Abstract: In some examples, a data protection system replicates write input/output (I/O) operations to entries of a journal stored in a storage system, and associates timers with the entries of the journal to provide timer-controlled immutability of the entries of the journal. Based on a first timer associated with a first entry of the entries of the journal indicating that a specified time duration has elapsed, the data protection system applies a first write I/O operation of the first entry to a backup data store that contains a copy of at least a portion of data in a primary data store. Prior to the first timer indicating that the specified time duration has elapsed, the data protection system prevents any modification of a storage location containing the first entry in the storage system.Type: ApplicationFiled: October 10, 2024Publication date: April 16, 2026Inventors: Omer Uretzky, Gil Barash
-
Patent number: 12585766Abstract: In some examples, a system identifies, from among a plurality of input/output (I/O) operations with a storage system, a subset of I/O operations involving encrypted data segments of a given data size. The system computes a measure based on a quantity of the I/O operations in the subset of I/O operations involving the encrypted data segments of the given data size. Based on the measure, the system determines whether an intermittent encryption attack is occurring with respect to the storage system.Type: GrantFiled: January 22, 2024Date of Patent: March 24, 2026Assignee: Hewlett Packard Enterprise Development LPInventors: Omer Uretzky, Gil Barash
-
Publication number: 20260065069Abstract: In some examples, a system replicates modified parameters of a machine learning model to a journal, where the modified parameters relate to elements of a graph structure of the machine learning model, and the modified parameters in the journal are to be applied to a backup representation of the machine learning model. Based on receipt of a query associated with recovering a version of the machine learning model, the system builds the version of the machine learning model by retrieving a selected modified parameter from among the modified parameters in the journal and merge the selected modified parameter with a copy of the machine learning model represented by the backup representation of the machine learning model.Type: ApplicationFiled: August 29, 2024Publication date: March 5, 2026Inventors: Omer Uretzky, Gil Barash
-
Publication number: 20260064544Abstract: In some examples, a system replicates a write event to a journal database, the write event involving a change of a source database including data points arranged in a multidimensional space. The replication of the write event adds a journal data point to the journal database. The journal data point includes write data of the write event and metadata indicating a write operation associated with the write data. Based on receipt of a recovery query associated with recovering data of the source database, the system obtains, according to a filter in the recovery query, a first result from the journal database and a second result from the backup database. The system merges the first result and the second result to produce a recovery result in response to the recovery query.Type: ApplicationFiled: August 29, 2024Publication date: March 5, 2026Inventors: Omer Uretzky, Gil Barash
-
Publication number: 20260064831Abstract: In some examples, a system receives a plurality of training samples of a training data set for a machine learning model, where each training sample of the plurality of training samples comprises a plurality of features. The system determines quantities of changes made to respective features of the plurality of features, computes a score representing an integrity of the training data set based on the quantities, and detects poisoning of the training data set based on the score.Type: ApplicationFiled: August 27, 2024Publication date: March 5, 2026Inventors: Omer Uretzky, Gil Barash, Amir Idar
-
Publication number: 20250238537Abstract: In some examples, a replication manager detects changed data caused by an input/output (I/O) operation, where the replication manager is to replicate data writes of I/O operations to a storage system. A classifier classifies the changed data to identify a sensitivity of the changed data. A system determines, based on the identified sensitivity of the changed data, an access control rule for a data object comprising the changed data. The system performs access control of the data object based on the determined access control rule.Type: ApplicationFiled: January 22, 2024Publication date: July 24, 2025Inventors: Omer Uretzky, Gil Barash, Gil Azrielant
-
Publication number: 20250238504Abstract: In some examples, a system identifies, from among a plurality of input/output (I/O) operations with a storage system, a subset of I/O operations involving encrypted data segments of a given data size. The system computes a measure based on a quantity of the I/O operations in the subset of I/O operations involving the encrypted data segments of the given data size. Based on the measure, the system determines whether an intermittent encryption attack is occurring with respect to the storage system.Type: ApplicationFiled: January 22, 2024Publication date: July 24, 2025Inventors: Omer Uretzky, Gil Barash
-
Publication number: 20250231919Abstract: Example implementations relate to data storage. An example includes detecting a trigger event for a reduction operation of a journal log, and in response selecting a set of target segments in the journal log. The example also includes determining a set of storage locations that were modified by write operations recorded in the set of target segments, and identifying a subset of journal entries in the set of target segments, where each journal entry of the subset of journal entries records a most recent write operation recorded for a different storage location of the set of storage locations. The example also includes generating a new segment including the identified subset of journal entries, and replacing the set of target segments with the generated new segment.Type: ApplicationFiled: January 16, 2024Publication date: July 17, 2025Inventors: Omer Uretzky, Gil Barash, Maya Leshem
-
Patent number: 12314589Abstract: Example implementations relate to data storage. An example includes inspecting a block level input/output (I/O) request to be executed by a block-based storage device, and in response to a determination that the block level I/O request includes a filesystem operation, generating a copy of the block level I/O request. The example also includes parsing the copy of the block level I/O request to extract a plurality of attributes of the filesystem operation, where the parsing is asynchronous to an execution of the block level I/O request by the block-based storage device. The example also includes storing the extracted plurality of attributes of the filesystem operation in an entry of a filesystem operation database, where each entry of the filesystem operation database is associated with a different filesystem operation in a filesystem stored on the block-based storage device.Type: GrantFiled: October 26, 2023Date of Patent: May 27, 2025Assignee: Hewlett Packard Enterprise Development LPInventors: Gil Barash, Shlomi Apel
-
Patent number: 12314393Abstract: Example implementations relate to storing data in a storage system. An example includes accessing a first portion of a data stream to be stored in a storage system; selecting sample data blocks included in the first portion; determining entropy values based on the sample data blocks; selecting, based on the sample data blocks, a entropy threshold from multiple precalculated entropy thresholds; determining whether the generated set of entropy values matches the selected entropy threshold within a probability level; and in response to a determination that the generated set of entropy values matches the selected entropy threshold within the probability level, identifying the first portion of the data stream as potentially including encrypted data affected by a ransomware attack.Type: GrantFiled: October 31, 2022Date of Patent: May 27, 2025Assignee: Hewlett Packard Enterprise Development LPInventors: Alex Veprinsky, Gil Barash, Oded Kedem