Patents by Inventor Ohad Korkus

Ohad Korkus has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20090265780
    Abstract: On-line and computationally efficient methods and systems are provided for back resolving path names of files from inode numbers during data access request processing. As a result, a near real-time recording of data access events is achieved, including identification of the user who performed the access, and the full path name of the data object that was accessed. In a typical application, access events are collected for use in access control of storage elements in complex organizational file systems.
    Type: Application
    Filed: April 21, 2008
    Publication date: October 22, 2009
    Applicant: Varonis Systems Inc.
    Inventors: Ohad Korkus, Yakov Faitelson, Ophir Kretzer, David Bass, Yizhar Keysar
  • Patent number: 7606801
    Abstract: Methods and systems are provided for defining and creating an automatic file security policy and a semi-automatic method of managing file access control in organizations with multiple diverse access control models and multiple diverse file server protocols. The system monitors access to storage elements within the network. The recorded data traffic is analyzed to assess simultaneous data access groupings and user groupings, which reflect the actual organizational structure. The learned structure is then transformed into a dynamic file security policy, which is constantly adapted to organizational changes over time. The system provides a decision assistance interface for interactive management of the file access control and for tracking abnormal user behavior.
    Type: Grant
    Filed: October 25, 2005
    Date of Patent: October 20, 2009
    Assignee: Varonis Inc.
    Inventors: Yakov Faitelson, Jacob Goldberger, Ohad Korkus
  • Patent number: 7555482
    Abstract: Methods and systems are provided for evaluating atypical user data access activities within the scope of an automatically generated file security policy in organizations with multiple diverse access control models and multiple diverse file server protocols. The system monitors access to storage elements within the network. The recorded data traffic is analyzed to assess simultaneous data access groupings and user groupings, which reflect the actual organizational structure. The learned structure is then transformed into a dynamic file security policy, which is constantly adapted to organizational changes over time. The system provides a decision assistance interface for tracking abnormal user behavior.
    Type: Grant
    Filed: December 7, 2006
    Date of Patent: June 30, 2009
    Assignee: Varonis Systems, Inc.
    Inventor: Ohad Korkus
  • Publication number: 20090119298
    Abstract: Queries regarding access permissions of users and rights to directories in a complex enterprise are executed in near realtime, using lookups to tables that form a condensed database maintained for each file server. User information is condensed by arranging users in user groups having common data access rights. Directory permissions storage is condensed by showing only distinctive permissions to a directory in a table entry, and referencing inherited permissions of parent directories. The tables indicate recursive and ancestral relationships among the user groups and directories. They are developed and updated in advance of any queries. A consolidated view of the query results is presented on a single display screen. Using the tables results can be obtained without exhaustive searches of large file system tables.
    Type: Application
    Filed: November 6, 2007
    Publication date: May 7, 2009
    Applicant: VARONIS SYSTEMS INC.
    Inventors: Yakov Faitelson, Ohad Korkus, Ophir Kretzer
  • Publication number: 20090100058
    Abstract: Queries regarding access permissions of users and rights to directories in a complex enterprise are executed in near real-time, using lookups to tables that form a condensed database maintained for each file server. User information is condensed by arranging users in user groups having common data access rights. Directory permissions storage is condensed by showing only distinctive permissions to a directory in a table entry, and referencing inherited permissions of parent directories. The tables indicate recursive and ancestral relationships among the user groups and directories. They are developed and updated in advance of any queries. A consolidated view of the query results is presented on a single display screen. Using the tables results can be obtained without exhaustive searches of large file system tables.
    Type: Application
    Filed: October 11, 2007
    Publication date: April 16, 2009
    Applicant: VARONIS INC.
    Inventors: Yakov Faitelson, Ohad Korkus, Ophir Kretzer
  • Publication number: 20080271157
    Abstract: Methods and systems are provided for controlling access to a file system. A record of actual accesses by users of the file system is maintained. Before a user is removed from a set of users or before a privilege for a set of users to access a data element is removed, it is determined whether the actual recorded accesses of the user are allowed by residual access permissions that would remain after implementing the proposed removal of access permission. An error condition is generated if the proposed removal of the access permission would have prevented at least one of the actual accesses. In another aspect of the invention, the system determines if the users would have alternate access to the storage element following implementation of the proposal.
    Type: Application
    Filed: April 26, 2007
    Publication date: October 30, 2008
    Inventors: Yakov Faitelson, Ohad Korkus, Ophir Kretzer
  • Publication number: 20070244899
    Abstract: Methods and systems are provided for decentralizing user data access rights control activities in networked organizations having diverse access control models and file server protocols. A folder management application enables end users of the file system to make requests for access to storage elements, either individually, or by becoming members of a user group having group access privileges. Responsibility for dealing with such requests is distributed to respective group owners and data owners, who may delegate responsibility to authorizers. The application may also consider automatically generated proposals for changes to access privileges. An automatic system continually monitors and analyzes access behavior by users who have been pre-classified into groups having common data access privileges. As the organizational structure changes, these groups are adaptively changed both in composition and in data access rights.
    Type: Application
    Filed: April 12, 2007
    Publication date: October 18, 2007
    Inventors: Yakov Faitelson, Ohad Korkus
  • Publication number: 20070094265
    Abstract: Methods and systems are provided for evaluating atypical user data access activities within the scope of an automatically generated file security policy in organizations with multiple diverse access control models and multiple diverse file server protocols. The system monitors access to storage elements within the network. The recorded data traffic is analyzed to assess simultaneous data access groupings and user groupings, which reflect the actual organizational structure. The learned structure is then transformed into a dynamic file security policy, which is constantly adapted to organizational changes over time. The system provides a decision assistance interface for tracking abnormal user behavior.
    Type: Application
    Filed: December 7, 2006
    Publication date: April 26, 2007
    Applicant: VARONIS SYSTEMS LTD.
    Inventor: Ohad Korkus
  • Publication number: 20060277184
    Abstract: Methods and systems are provided for defining and creating an automatic file security policy and a semi-automatic method of managing file access control in organizations with multiple diverse access control models and multiple diverse file server protocols. The system monitors access to storage elements within the network. The recorded data traffic is analyzed to assess simultaneous data access groupings and user groupings, which reflect the actual organizational structure. The learned structure is then transformed into a dynamic file security policy, which is constantly adapted to organizational changes over time. The system provides a decision assistance interface for interactive management of the file access control and for tracking abnormal user behavior.
    Type: Application
    Filed: October 25, 2005
    Publication date: December 7, 2006
    Applicant: VARONIS SYSTEMS LTD.
    Inventors: Yakov Faitelson, Jacob Goldberger, Ohad Korkus