Patents by Inventor Guy Franco

Guy Franco has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20260140718
    Abstract: A system and method for identifying and mitigating a vulnerable software library is presented. The method includes querying a data structure using an identifier that represents a function, wherein the data structure has a plurality of keys that each corresponds to a specific software library deployed in an application runtime environment and common to functions of the specific software library; mapping a portion of the identifier to a first key of the plurality of keys in the data structure, wherein the first key corresponds to a first library; identifying, based on the mapping, the first library for the function represented by the identifier; determining a vulnerability based on the identified first library deployed in the application runtime environment; and causing a mitigation against the first library that is determined to have vulnerability.
    Type: Application
    Filed: December 9, 2025
    Publication date: May 21, 2026
    Applicant: R.C.Raven Cloud LTD
    Inventors: Roi ABITBOUL, Guy FRANCO, Shani GOLDBERG, Omer YAIR
  • Patent number: 12619449
    Abstract: A system and method for generating a compact unwinding table for call stack unwinding is provided. The method includes extracting a plurality of instruction entries and an offset value for each of the plurality of instruction entries from at least one frame description entry (FDE), wherein each of the at least one FDE contains information for the plurality of instruction entries; selecting a subset of the extracted plurality of instruction entries, wherein the subset includes relevant instruction entries for unwinding; generating the compact unwinding table based on the subset to include the instruction entries and respective offset values; and storing the generated compact unwinding table with respect to a source binary file.
    Type: Grant
    Filed: March 8, 2024
    Date of Patent: May 5, 2026
    Assignee: R.C.Raven Cloud LTD
    Inventors: Guy Franco, Omer Yair
  • Publication number: 20260023668
    Abstract: A system and method for efficiently tracking unwound call stacks with reduced cardinality is presented. The method includes retrieving an unwinding table based on a first address of a current context received from a system event, wherein the first address indicates a source binary file; identifying a lower limit address and an upper limit address from the retrieved unwinding table, wherein the first address is bound between the lower limit address and the upper limit address; constructing an unwound call stack from a top stack frame including the lower limit address; and storing the constructed unwound call stack with the top stack frame in a memory.
    Type: Application
    Filed: July 19, 2024
    Publication date: January 22, 2026
    Applicant: R.C.Raven Cloud LTD
    Inventors: Guy FRANCO, Omer YAIR
  • Patent number: 12524534
    Abstract: A system and method for efficiently detecting an exploitation during a workload runtime is presented. The method includes fetching a library call chain that has at least a first library, wherein the library call chain is a series of software libraries that are employed in executing the workload at the runtime, wherein the library call chain is fetched based on a trigger of an event at the workload runtime; determining a hash value for the fetched library call chain, wherein the hash value is a numerical representation of the library call chain that has at least the first library; checking the determined hash value against a policy for a match; detecting an exploit in the library call chain upon determining a mismatch between the determined hash value and the policy; and causing an execution of a mitigation action.
    Type: Grant
    Filed: April 17, 2025
    Date of Patent: January 13, 2026
    Assignee: R.C.Raven Cloud LTD
    Inventors: Roi Abitboul, Guy Franco, Leonid Frenkel, Omer Yair
  • Patent number: 12517706
    Abstract: A system and method for identifying open source software (OSS) libraries for an application runtime environment is presented. The method includes receiving an identifier representing a function of the application runtime environment as a sequence of bits; querying a tree-like data structure using the received identifier; matching a portion of the identifier to a first key of the data structure that has a prefix of the identifier; and identifying a library of the function represented by the received identifier.
    Type: Grant
    Filed: November 20, 2024
    Date of Patent: January 6, 2026
    Assignee: R.C. Raven Cloud LTD
    Inventors: Roi Abitboul, Guy Franco, Shani Goldberg, Omer Yair
  • Publication number: 20250217666
    Abstract: A system and method for identifying a request of a service. The method includes generating vector embeddings for raw data of events using a machine learning model, wherein the machine learning model is trained to indicate semantic meaning of at least one event of the raw data of events; clustering, based on the vector embeddings, the at least one event of the raw data of events into a plurality of clusters, wherein a subset of the plurality of clusters includes relevant events in the data of events; and identifying a request as a sequence of events from the subset of the plurality of clusters.
    Type: Application
    Filed: December 28, 2023
    Publication date: July 3, 2025
    Applicant: R.C.Raven Cloud LTD
    Inventors: Roi ABITBOUL, Guy FRANCO, Roland DANIELYAN, Omer YAIR
  • Publication number: 20250138969
    Abstract: A system and method for determining an optimization opportunity in request performances is presented. The method includes extracting a first event with an inherent delay and a first thread of a request including the first event, wherein the inherent delay is identified by monitoring a duration of the first event above a threshold percentile; determining an event contribution for at least one second event that is an event of at least one second thread of the request, wherein the event contribution is determined for a request occurrence; statistically determining an event performance for each of the at least one second event based on aggregated event contributions for the at least one second event; identifying an optimization opportunity for the request based on the event performance beyond a predefined range; and generating a report to include identified optimization opportunity for the request.
    Type: Application
    Filed: October 27, 2023
    Publication date: May 1, 2025
    Applicant: R.C.Raven Cloud LTD
    Inventors: Roi ABITBOUL, Guy FRANCO, Yanna GOTTLIEB, Omer YAIR
  • Publication number: 20210334612
    Abstract: In an example, a method includes selecting a unique identifier corresponding to a set of rules. At least one modified image is generated from a seed image using a processor by determining and applying an image attribute modification to the seed image according to at least one rule in the set of rules of the unique identifier. The modified image is placed in a predefined position according to at least one rule in the set of rules of the unique identifier.
    Type: Application
    Filed: June 5, 2018
    Publication date: October 28, 2021
    Inventors: Amir Gaash, Ori Levron, Guy Franco, Guy Bibi, Chen Peretz, Shai Rubin
  • Patent number: 10637864
    Abstract: Introduced here are security techniques for networks. More specifically, fictitious identities (also referred to as “bogus identities”) can be willfully created and injected into the network in order to obfuscate those who are not authorized to access the network. For example, such techniques may be used to befuddle hackers attempting to breach an internal network. The fictitious identities can be created by bypassing the operating system of computing device(s) residing within the network and deploying the fictitious identities within an operating system process responsible for implementing a security policy. Such action utilizes a limited amount of memory. The fictitious identities create a false visual of the network that is visible to any threat, regardless of where the threat is located in the network. Moreover, the fictitious identities may not infringe upon the topology of the network or affect the ability of authenticated users to continue using the network.
    Type: Grant
    Filed: May 5, 2017
    Date of Patent: April 28, 2020
    Assignee: CA, Inc.
    Inventors: Almog Ohayon, Guy Franco, Roi Abutbul
  • Patent number: 10515187
    Abstract: Introduced here are techniques for modeling networks in a discrete manner. More specifically, various embodiments concern a virtual machine that collects data regarding a network and applies algorithms to the data to discover network elements, which can be used to discover the topology of the network and model the network. The algorithms applied by the virtual machine may also recognize patterns within the data corresponding to naming schemes, subnet structures, application logic, etc. In some embodiments, the algorithms employ artificial intelligence techniques in order to more promptly respond to changes in the data. The virtual machine may only have read-only access to certain objects residing within the network. For example, the virtual machine may be able to examine information hosted by a directory server, but the virtual machine may not be able to effect any changes to the information.
    Type: Grant
    Filed: June 29, 2017
    Date of Patent: December 24, 2019
    Assignee: Symantec Corporation
    Inventors: Almog Ohayon, Guy Franco, Roi Abutbul
  • Patent number: 10474788
    Abstract: Introduced here are techniques for modeling networks in a discrete manner. More specifically, various embodiments concern a virtual machine that collects data regarding a network and applies algorithms to the data to discover network elements, which can be used to discover the topology of the network and model the network. The algorithms applied by the virtual machine may also recognize patterns within the data corresponding to naming schemes, subnet structures, application logic, etc. In some embodiments, the algorithms employ artificial intelligence techniques in order to more promptly respond to changes in the data. The virtual machine may only have read-only access to certain objects residing within the network. For example, the virtual machine may be able to examine information hosted by a directory server, but the virtual machine may not be able to effect any changes to the information.
    Type: Grant
    Filed: June 29, 2017
    Date of Patent: November 12, 2019
    Assignee: Symantec Corporation
    Inventors: Almog Ohayon, Guy Franco, Roi Abutbul
  • Publication number: 20180004870
    Abstract: Introduced here are techniques for modeling networks in a discrete manner. More specifically, various embodiments concern a virtual machine that collects data regarding a network and applies algorithms to the data to discover network elements, which can be used to discover the topology of the network and model the network. The algorithms applied by the virtual machine may also recognize patterns within the data corresponding to naming schemes, subnet structures, application logic, etc. In some embodiments, the algorithms employ artificial intelligence techniques in order to more promptly respond to changes in the data. The virtual machine may only have read-only access to certain objects residing within the network. For example, the virtual machine may be able to examine information hosted by a directory server, but the virtual machine may not be able to effect any changes to the information.
    Type: Application
    Filed: June 29, 2017
    Publication date: January 4, 2018
    Inventors: Almog Ohayon, Guy Franco, Roi Abutbul
  • Publication number: 20170324777
    Abstract: Various embodiments pertain to techniques for injecting supplemental data into search query results delivered to an operating system. More specifically, an operating system can submit a search query to a directory server (or some other network-accessible database), and then pass results of the search query to a local proxy. The local proxy can inject supplemental data into the results. For example, the local proxy could inject bogus user account information in an effort to obfuscate an unauthorized entity who attempts to penetrate the network by parsing the results of the search query.
    Type: Application
    Filed: July 13, 2017
    Publication date: November 9, 2017
    Inventors: Almog Ohayon, Guy Franco, Roi Abutbul
  • Publication number: 20170324773
    Abstract: Introduced here are security techniques for networks. More specifically, fictitious identities (also referred to as “bogus identities”) can be willfully created and injected into the network in order to obfuscate those who are not authorized to access the network. For example, such techniques may be used to befuddle hackers attempting to breach an internal network. The fictitious identities can be created by bypassing the operating system of computing device(s) residing within the network and deploying the fictitious identities within an operating system process responsible for implementing a security policy. Such action utilizes a limited amount of memory. The fictitious identities create a false visual of the network that is visible to any threat, regardless of where the threat is located in the network. Moreover, the fictitious identities may not infringe upon the topology of the network or affect the ability of authenticated users to continue using the network.
    Type: Application
    Filed: May 5, 2017
    Publication date: November 9, 2017
    Inventors: Almog Ohayon, Guy Franco, Roi Abutbul
  • Publication number: 20170324774
    Abstract: Various embodiments are described herein that add supplemental data into security-related query results delivered to an operating system. More specifically, an operating system can submit a security-related query to a directory server (or some other network-accessible database), and then pass results of the security-related query to a local proxy. The local proxy can add supplemental data into the results. For example, the local proxy could add bogus directory information in an effort to obfuscate an attempt to gain access to network data by an unauthorized entity who attempts to penetrate the network by parsing the results of the security-related query.
    Type: Application
    Filed: July 19, 2017
    Publication date: November 9, 2017
    Inventors: Almog Ohayon, Guy Franco, Roi Abutbul