Patents by Inventor Guy Teverovsky
Guy Teverovsky has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Publication number: 20260238670Abstract: A method includes identifying, by at least one processing device, at least one security zone comprising an initial set of objects of a computing environment, determining, by the at least one processing device, whether at least one valid object for inclusion in the at least one security zone exists, in response to determining that the at least one valid object for inclusion in the at least one security zone exists, adding, by the at least one processing device, the at least one valid object to the initial set of objects, and performing, by the at least one processing device based on the set of attack paths, attack path risk mitigation.Type: ApplicationFiled: April 3, 2026Publication date: August 13, 2026Inventors: Igor Baikalov, Guy Teverovsky, Gil Kirkpatrick, Elad Shamir
-
Publication number: 20260238671Abstract: A method includes identifying, by at least one processing device, a set of attack paths within a computing environment, each attack path connecting a source object to a target object through one or more control relationships having respective control relationship costs, wherein each cost indicates the difficulty for an attacker to progress from a first object to a second object via the associated control relationship. The method further includes determining, for each attack path based on the control relationship costs, a respective attack path cost, and determining, for each attack path based at least in part on the attack path costs, a respective attack path risk metric, wherein a lower attack path cost corresponds to a higher attack path risk metric. The method also includes performing attack path risk mitigation based on the attack path risk metrics.Type: ApplicationFiled: April 3, 2026Publication date: August 13, 2026Inventors: Igor Baikalov, Guy Teverovsky, Gil Kirkpatrick, Elad Shamir
-
Patent number: 12634314Abstract: A method includes generating, by a processing device, at least one security zone comprising a set of objects of a computing environment using at least one identity system, and identifying, by the processing device, a set of attack paths leading to the at least one security zone. Each attack path of the set of attack paths includes a respective target object accessible via a respective source object through at least one control relationship, and each target object is included within the set of objects of the at least one security zone. The method further includes performing, by the processing device based on the set of attack paths, attack path monitoring and risk mitigation.Type: GrantFiled: June 23, 2023Date of Patent: May 19, 2026Assignee: SEMPERIS LTD.Inventors: Igor Baikalov, Guy Teverovsky, Gil Kirkpatrick, Elad Shamir
-
Publication number: 20240031391Abstract: A method includes generating, by a processing device, at least one security zone comprising a set of objects of a computing environment using at least one identity system, and identifying, by the processing device, a set of attack paths leading to the at least one security zone. Each attack path of the set of attack paths includes a respective target object accessible via a respective source object through at least one control relationship, and each target object is included within the set of objects of the at least one security zone. The method further includes performing, by the processing device based on the set of attack paths, attack path monitoring and risk mitigation.Type: ApplicationFiled: June 23, 2023Publication date: January 25, 2024Inventors: Igor Baikalov, Guy Teverovsky, Gil Kirkpatrick, Elad Shamir
-
Patent number: 11070516Abstract: Technology for analyzing and tracking states of a directory service by correlating changes from multiple different data sources related to the directory service. A first data source may be based on synchronization data of the directory service and a second data source may be based on security data of one or more domain controllers hosting the directory service. The synchronization data and security data may both correspond to changes to the directory service but may include different information. For example, synchronization data may provide the content of a modification to the directory service and the security data may provide an entity that initiated the modification. The multiple sources may be compared to identify inconsistencies (e.g., detect malicious activity).Type: GrantFiled: January 28, 2020Date of Patent: July 20, 2021Assignee: SemperisInventors: Guy Teverovsky, Dan Croitoru, Matan Liberman, Michael Bresman, Darren Mar-Elia
-
Publication number: 20200169529Abstract: Technology for analyzing and tracking states of a directory service by correlating changes from multiple different data sources related to the directory service. A first data source may be based on synchronization data of the directory service and a second data source may be based on security data of one or more domain controllers hosting the directory service. The synchronization data and security data may both correspond to changes to the directory service but may include different information. For example, synchronization data may provide the content of a modification to the directory service and the security data may provide an entity that initiated the modification. The multiple sources may be compared to identify inconsistencies (e.g., detect malicious activity).Type: ApplicationFiled: January 28, 2020Publication date: May 28, 2020Inventors: Guy Teverovsky, Dan Croitoru, Matan Liberman, Michael Bresman, Darren Mar-Elia
-
Patent number: 10554615Abstract: Technology for analyzing and tracking states of a directory service by correlating changes from multiple different data sources related to the directory service. A first data source may be based on synchronization data of the directory service and a second data source may be based on security data of one or more domain controllers hosting the directory service. The synchronization data and security data may both correspond to changes to the directory service but may include different information. For example, synchronization data may provide the content of a modification to the directory service and the security data may provide an entity that initiated the modification. The multiple sources may be used to generate and enrich modification data of the directory service. The modification data may be used to determine a prior state of the directory service, to undue modifications initiated by a particular user, or to detect malicious activity.Type: GrantFiled: March 8, 2018Date of Patent: February 4, 2020Assignee: SEMPERISInventors: Guy Teverovsky, Dan Croitoru, Matan Liberman, Michael Bresman, Darren Mar-Elia
-
Publication number: 20190281010Abstract: Technology for analyzing and tracking states of a directory service by correlating changes from multiple different data sources related to the directory service. A first data source may be based on synchronization data of the directory service and a second data source may be based on security data of one or more domain controllers hosting the directory service. The synchronization data and security data may both correspond to changes to the directory service but may include different information. For example, synchronization data may provide the content of a modification to the directory service and the security data may provide an entity that initiated the modification. The multiple sources may be used to generate and enrich modification data of the directory service. The modification data may be used to determine a prior state of the directory service, to undue modifications initiated by a particular user, or to detect malicious activity.Type: ApplicationFiled: March 8, 2018Publication date: September 12, 2019Inventors: Guy Teverovsky, Dan Croitoru, Matan Liberman, Michael Bresman, Darren Mar-Elia
-
Patent number: 10346085Abstract: Technology for backing up and restoring directory services that have a domain hierarchy (e.g., a domain forest). The technology may analyze operating system level backup data of multiple domain controllers and decouple data of the directory service from the backup data. The decoupled data may be absent executable data and may represent the backed up state of the directory service. The decoupled data may be enriched to include additional information about the computing environment and stored in a storage object (e.g., a forest recovery object). The technology may use the storage object to restore the directory service to the same set of computing devices or to a different set of computing device. This may involve configuring one or more of the computing devices to support directory services and coordinating an update to the configured computing devices to restore the backed up state of the directory service.Type: GrantFiled: February 7, 2019Date of Patent: July 9, 2019Assignee: SemperisInventors: Guy Teverovsky, Matan Liberman, Michael Bresman