Patents by Inventor Oded Comay
Oded Comay has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Publication number: 20250030715Abstract: Systems, methods, and related technologies for analyzing traffic are described. In certain aspects, network traffic is analyzed and a domain name system (DNS) message is extracted from the network traffic. Subsequent network traffic is monitored and analyzed based on the DNS message and in view of one or more criteria. In response to the one or more criteria being satisfied, an indication of compromise (IoC) for a device is determined.Type: ApplicationFiled: February 26, 2024Publication date: January 23, 2025Inventors: Oded Comay, Oren Nechushtan
-
Patent number: 12028371Abstract: Systems, methods, and related technologies including media access control (MAC) address spoofing detection are described. The MAC address spoofing detection and response may include accessing a first MAC address associated with a first communication on a first port of a first network device and accessing a second MAC address associated with a second communication on a second port of a second network device. Whether the first MAC address and the second MAC address match may be determined. Information associated with a third communication associated with the first MAC address on the first port of the first network device and information associated with a fourth communication associated with the second MAC address on the second port of the second network device may be accessed. An action may be performed associated with the second port of the second network device based on the second MAC address matching the first MAC address.Type: GrantFiled: April 28, 2022Date of Patent: July 2, 2024Assignee: FORESCOUT TECHNOLOGIES, INC.Inventors: Ilya Fainberg, Abdelhamid Masarwa, Oren Nechushtan, Oded Comay
-
Patent number: 11916943Abstract: Systems, methods, and related technologies for analyzing traffic based on naming information are described. In certain aspects, name information and address information from a name translation response are stored. The name information is associated with a device based on the device sending a communication to an address associated with the name information.Type: GrantFiled: August 2, 2021Date of Patent: February 27, 2024Assignee: FORESCOUT TECHNOLOGIES, INC.Inventors: Oded Comay, Oren Nechushtan
-
Publication number: 20230421466Abstract: Systems, methods, and related technologies for generating a network system map based on network traffic and possibly additional data are described. Network traffic may be received and parsed to obtain metadata associated with the network traffic. A network system may be identified based on the metadata. A network system map may be generated for the network system based on one or more of the metadata or the additional data.Type: ApplicationFiled: September 11, 2023Publication date: December 28, 2023Inventors: Oren Nechushtan, Oded Comay
-
Patent number: 11792093Abstract: Systems, methods, and related technologies for generating a network system map based on network traffic and possibly additional data are described. Network traffic may be received and parsed to obtain metadata associated with the network traffic. A network system may be identified based on the metadata. A network system map may be generated for the network system based on one or more of the metadata or the additional data.Type: GrantFiled: July 23, 2021Date of Patent: October 17, 2023Assignee: FORESCOUT TECHNOLOGIES, INC.Inventors: Oren Nechushtan, Oded Comay
-
Publication number: 20230009167Abstract: A network access control (NAC) device detects a connection of an endpoint device at a network switch coupled to a network and restricts access of the endpoint device to prevent the endpoint device from accessing resources of the network. The NAC device establishes a connection with the endpoint device, validates a client certificate corresponding to the endpoint device to authenticate the endpoint device as a corporate device and grants the endpoint device access to the resources of the network.Type: ApplicationFiled: July 21, 2022Publication date: January 12, 2023Inventors: Oded Comay, Kevin Benjamin Mayer, Oren Nechushtan, Tomer Reisner
-
Publication number: 20230006899Abstract: Systems, methods, and related technologies for generating a network system map based on network traffic and possibly additional data are described. Network traffic may be received and parsed to obtain metadata associated with the network traffic. A network system may be identified based on the metadata. A network system map may be generated for the network system based on one or more of the metadata or the additional data.Type: ApplicationFiled: July 23, 2021Publication date: January 5, 2023Inventors: Oren Nechushtan, Oded Comay
-
Publication number: 20220255960Abstract: Systems, methods, and related technologies including media access control (MAC) address spoofing detection are described. The MAC address spoofing detection and response may include accessing a first MAC address associated with a first communication on a first port of a first network device and accessing a second MAC address associated with a second communication on a second port of a second network device. Whether the first MAC address and the second MAC address match may be determined. Information associated with a third communication associated with the first MAC address on the first port of the first network device and information associated with a fourth communication associated with the second MAC address on the second port of the second network device may be accessed. An action may be performed associated with the second port of the second network device based on the second MAC address matching the first MAC address.Type: ApplicationFiled: April 28, 2022Publication date: August 11, 2022Inventors: Ilya Fainberg, Abdelhamid Masarwa, Oren Nechushtan, Oded Comay
-
Patent number: 11405378Abstract: A network access control (NAC) device detects a connection of an endpoint device at a network switch coupled to a network and restricts access of the endpoint device to prevent the endpoint device from accessing resources of the network. The NAC device establishes a connection with the endpoint device, validates a client certificate corresponding to the endpoint device to authenticate the endpoint device as a corporate device and grants the endpoint device access to the resources of the network.Type: GrantFiled: December 11, 2019Date of Patent: August 2, 2022Assignee: Forescout Technologies, Inc.Inventors: Oded Comay, Kevin Benjamin Mayer, Oren Nechushtan, Tomer Reisner
-
Patent number: 11349867Abstract: Systems, methods, and related technologies including media access control (MAC) address spoofing detection are described. The MAC address spoofing detection and response may include accessing a first MAC address associated with a first communication on a first port of a first network device and accessing a second MAC address associated with a second communication on a second port of a second network device. Whether the first MAC address and the second MAC address match may be determined. Information associated with a third communication associated with the first MAC address on the first port of the first network device and information associated with a fourth communication associated with the second MAC address on the second port of the second network device may be accessed. An action may be performed associated with the second port of the second network device based on the second MAC address matching the first MAC address.Type: GrantFiled: December 31, 2018Date of Patent: May 31, 2022Assignee: Forescout Technologies, Inc.Inventors: Ilya Fainberg, Abdelhamid Masarwa, Oren Nechushtan, Oded Comay
-
Publication number: 20210367960Abstract: Systems, methods, and related technologies for analyzing traffic based on naming information are described. In certain aspects, name information and address information from a name translation response are stored. The name information is associated with a device based on the device sending a communication to an address associated with the name information.Type: ApplicationFiled: August 2, 2021Publication date: November 25, 2021Inventors: Oded Comay, Oren Nechushtan
-
Patent number: 11108799Abstract: Systems, methods, and related technologies for analyzing traffic based on naming information are described. In certain aspects, name information and address information from a name translation response are stored. The name information is associated with a device based on the device sending a communication to an address associated with the name information.Type: GrantFiled: January 24, 2020Date of Patent: August 31, 2021Assignee: FORESCOUT TECHNOLOGIES, INC.Inventors: Oded Comay, Oren Nechushtan
-
Publication number: 20200213352Abstract: Systems, methods, and related technologies including media access control (MAC) address spoofing detection are described. The MAC address spoofing detection and response may include accessing a first MAC address associated with a first communication on a first port of a first network device and accessing a second MAC address associated with a second communication on a second port of a second network device. Whether the first MAC address and the second MAC address match may be determined. Information associated with a third communication associated with the first MAC address on the first port of the first network device and information associated with a fourth communication associated with the second MAC address on the second port of the second network device may be accessed. An action may be performed associated with the second port of the second network device based on the second MAC address matching the first MAC address.Type: ApplicationFiled: December 31, 2018Publication date: July 2, 2020Inventors: Ilya Fainberg, Abdelhamid Masarwa, Oren Nechushtan, Oded Comay
-
Publication number: 20200162495Abstract: Systems, methods, and related technologies for analyzing traffic based on naming information are described. In certain aspects, name information and address information from a name translation response are stored. The name information is associated with a device based on the device sending a communication to an address associated with the name information.Type: ApplicationFiled: January 24, 2020Publication date: May 21, 2020Inventors: Oded Comay, Oren Nechushtan
-
Publication number: 20200120085Abstract: A network access control (NAC) device detects a connection of an endpoint device at a network switch coupled to a network and restricts access of the endpoint device to prevent the endpoint device from accessing resources of the network. The NAC device establishes a connection with the endpoint device, validates a client certificate corresponding to the endpoint device to authenticate the endpoint device as a corporate device and grants the endpoint device access to the resources of the network.Type: ApplicationFiled: December 11, 2019Publication date: April 16, 2020Inventors: Oded Comay, Kevin Benjamin Mayer, Oren Nechushtan, Tomer Reisner
-
Patent number: 10574678Abstract: Systems, methods, and related technologies for analyzing traffic based on naming information are described. In certain aspects, name information and address information from a name translation response are stored. The name information is associated with a device based on the device sending a communication to an address associated with the name information.Type: GrantFiled: December 13, 2016Date of Patent: February 25, 2020Assignee: Forescout Technologies, Inc.Inventors: Oded Comay, Oren Nechushtan
-
Patent number: 10530764Abstract: A network access control (NAC) device detects a connection of an endpoint device at a network switch coupled to a network and restricts access of the endpoint device to prevent the endpoint device from accessing resources of the network. The NAC device establishes a connection with the endpoint device, validates a client certificate corresponding to the endpoint device to authenticate the endpoint device as a corporate device and grants the endpoint device access to the resources of the network.Type: GrantFiled: December 19, 2016Date of Patent: January 7, 2020Assignee: FORESCOUT TECHNOLOGIES, INC.Inventors: Oded Comay, Kevin Benjamin Mayer, Oren Nechushtan, Tomer Reisner
-
Publication number: 20180176210Abstract: A network access control (NAC) device detects a connection of an endpoint device at a network switch coupled to a network and restricts access of the endpoint device to prevent the endpoint device from accessing resources of the network. The NAC device establishes a connection with the endpoint device, validates a client certificate corresponding to the endpoint device to authenticate the endpoint device as a corporate device and grants the endpoint device access to the resources of the network.Type: ApplicationFiled: December 19, 2016Publication date: June 21, 2018Inventors: Oded Comay, Kevin Benjamin Mayer, Oren Nechushtan, Tomer Reisner
-
Publication number: 20180167405Abstract: Systems, methods, and related technologies for analyzing traffic based on naming information are described. In certain aspects, name information and address information from a name translation response are stored. The name information is associated with a device based on the device sending a communication to an address associated with the name information.Type: ApplicationFiled: December 13, 2016Publication date: June 14, 2018Inventors: Oded Comay, Oren Nechushtan
-
Patent number: 9027079Abstract: Disclosed is a method and system for network access control, including an authentication proxy that authenticates different access-points, retrieves data from security databases and from Network Monitoring Systems, processing said data according to a dynamic security policy and using said processing outcome to determine the access level which will be granted to an access point in the network.Type: GrantFiled: November 18, 2013Date of Patent: May 5, 2015Assignee: ForeScout Technologies, Inc.Inventors: Oded Comay, Doron Shikmoni