Patents by Inventor Ruth Bernstein

Ruth Bernstein has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 10796444
    Abstract: Systems, and method and computer readable media that store instructions for calculating signatures, utilizing signatures and the like.
    Type: Grant
    Filed: November 17, 2019
    Date of Patent: October 6, 2020
    Inventors: Igal Raichelgauz, Ruth Bernstein
  • Publication number: 20200311960
    Abstract: Systems, and method and computer readable media that store instructions for calculating signatures, utilizing signatures and the like.
    Type: Application
    Filed: November 17, 2019
    Publication date: October 1, 2020
    Inventors: IGAL RAICHELGAUZ, Ruth Bernstein
  • Patent number: 9690645
    Abstract: Determining suspected root causes of anomalous network behavior includes identifying anomalous components in a network exhibiting anomalous behavior from a plurality of network components, assigning a likelihood score to network components based on a scoring policy that considers recent change events affecting the anomalous components, and identifying a subset of the network components that are suspected to be root causes based on the likelihood score.
    Type: Grant
    Filed: December 4, 2012
    Date of Patent: June 27, 2017
    Assignee: Hewlett Packard Enterprise Development LP
    Inventors: Eran Samuni, Ira Cohen, Ruth Bernstein
  • Patent number: 9565203
    Abstract: There is provided a computer implemented method for detecting anomalous behavior in a network, comprising: receiving data representing at least one network activity, each network activity representing a certain data access event involving certain network entities; extracting from the data the certain network entities involved in the respective network activity; retrieving at least one relevant diversity value from a network behavior model based on the extracted certain network entities, wherein the network behavior model includes at least one diversity value, wherein each respective diversity value represents a certain relationship between at least one network entity and at least one network entity type; calculating an abnormality score for the received network activity based on the retrieved relevant diversity values; and classifying the network activity as anomalous or normal based on the calculated abnormality score.
    Type: Grant
    Filed: November 13, 2014
    Date of Patent: February 7, 2017
    Assignee: Cyber-Ark Software Ltd.
    Inventors: Ruth Bernstein, Andrey Dulkin
  • Patent number: 9497206
    Abstract: A method for identifying anomalies in a group of network addresses includes building a model of the group of network addresses and identifying a network address as anomalous based on the deviation of the network address from the model. The model is built from a group of network addresses. The network addresses are input and parsed into one or more address trees. A ripeness score is maintained for each of the nodes in the address trees, based, at least in part, on the number of occurrences of the network address portion represented by the node. Nodes having respective ripeness scores within a specified range are classified as ripe nodes, and may be indicative of normal behavior, and nodes having respective ripeness scores outside the specified range of ripeness scores are classified as unripe, and may be indicative of anomalous behavior.
    Type: Grant
    Filed: April 16, 2014
    Date of Patent: November 15, 2016
    Assignee: Cyber-Ark Software Ltd.
    Inventors: Ruth Bernstein, Andrey Dulkin, Assaf Weiss, Aviram Shmueli
  • Publication number: 20160162348
    Abstract: A method for automated detection of a real IT system problem may include obtaining monitor measurements of metrics associated with activities of a plurality of configuration items of the IT system. The method may also include detecting anomalies in the monitor measurements. The method may further include grouping concurrent anomalies of the detected anomalies corresponding to configuration items of the plurality of configuration items which are topologically linked to be regarded as a system anomaly. The method may further include calculating a significance score for the system anomaly, and determining that the system anomaly relates to a real system problem based on the calculated significance score.
    Type: Application
    Filed: February 9, 2016
    Publication date: June 9, 2016
    Inventors: Ruth Bernstein, Ira Cohen, Eran Samuni
  • Publication number: 20160142435
    Abstract: There is provided a computer implemented method for detecting anomalous behavior in a network, comprising: receiving data representing at least one network activity, each network activity representing a certain data access event involving certain network entities; extracting from the data the certain network entities involved in the respective network activity; retrieving at least one relevant diversity value from a network behavior model based on the extracted certain network entities, wherein the network behavior model includes at least one diversity value, wherein each respective diversity value represents a certain relationship between at least one network entity and at least one network entity type; calculating an abnormality score for the received network activity based on the retrieved relevant diversity values; and classifying the network activity as anomalous or normal based on the calculated abnormality score.
    Type: Application
    Filed: November 13, 2014
    Publication date: May 19, 2016
    Inventors: Ruth BERNSTEIN, Andrey Dulkin
  • Patent number: 9292408
    Abstract: A method for automated detection of a real IT system problem may include obtaining monitor measurements of metrics associated with activities of a plurality of configuration items of the IT system. The method may also include detecting anomalies in the monitor measurements. The method may further include grouping concurrent anomalies of the detected anomalies corresponding to configuration items of the plurality of configuration items which are topologically linked to be regarded as a system anomaly. The method may further include calculating a significance score for the system anomaly, and determining that the system anomaly relates to a real system problem based on the calculated significance score.
    Type: Grant
    Filed: September 21, 2011
    Date of Patent: March 22, 2016
    Assignee: Hewlett Packard Enterprise Development LP
    Inventors: Ruth Bernstein, Ira Cohen, Eran Samuni
  • Publication number: 20150347214
    Abstract: Determining suspected root causes of anomalous network behavior includes identifying anomalous components in a network exhibiting anomalous behavior from a plurality of network components, assigning a likelihood score to network components based on a scoring policy that considers recent change events affecting the anomalous components, and identifying a subset of the network components that are suspected to be root causes based on the likelihood score.
    Type: Application
    Filed: December 4, 2012
    Publication date: December 3, 2015
    Inventors: Eran Samuni, Ira Cohen, Ruth Bernstein
  • Publication number: 20150304349
    Abstract: A method for identifying anomalies in a group of network addresses includes building a model of the group of network addresses and identifying a network address as anomalous based on the deviation of the network address from the model. The model is built from a group of network addresses. The network addresses are input and parsed into one or more address trees. A ripeness score is maintained for each of the nodes in the address trees, based, at least in part, on the number of occurrences of the network address portion represented by the node. Nodes having respective ripeness scores within a specified range are classified as ripe nodes, and may be indicative of normal behavior, and nodes having respective ripeness scores outside the specified range of ripeness scores are classified as unripe, and may be indicative of anomalous behavior.
    Type: Application
    Filed: April 16, 2014
    Publication date: October 22, 2015
    Applicant: Cyber-Ark Software Ltd.
    Inventors: Ruth Bernstein, Andrey Dulkin, Assaf Weiss, Aviram Shmueli
  • Patent number: 9087089
    Abstract: A method and system comprise abstracting configuration items (CI) in at least a first anomaly and a second anomaly based on type of CI. Further, CIs are matched of a common type between the first and second anomalies based on a cost function. Additionally, a similarity score is computed for the first and second anomalies based, at least in part, on the cost function of the matched CI's and based on topology of the first and second anomalies.
    Type: Grant
    Filed: June 9, 2010
    Date of Patent: July 21, 2015
    Assignee: Hewlett-Packard Development Company, L.P.
    Inventors: Ruth Bernstein, Ira Cohen, Chen Kahana
  • Patent number: 8930773
    Abstract: Methods, systems, and computer-readable media with executable instructions stored thereon for determining root cause are provided. A method for determining root cause can include receiving values for at least one performance metric for each of a plurality of components of an IT system to establish a normal value for each of the performance metrics, receiving an abnormal value that differs from the normal value for at least one of the plurality of components of the IT system, and determining a probability that the at least one of the plurality of components of the IT system is a root cause of the abnormal value.
    Type: Grant
    Filed: April 16, 2012
    Date of Patent: January 6, 2015
    Assignee: Hewlett-Packard Development Company, L.P.
    Inventors: Ruth Bernstein, Ira Cohen, Eran Samuni, Keren Gattegno
  • Patent number: 8924797
    Abstract: At least one value of abnormal metrics is identified as being an abnormal dimension value. A dominant dimension related to the anomaly is identified based on the identified abnormal dimension value.
    Type: Grant
    Filed: April 16, 2012
    Date of Patent: December 30, 2014
    Assignee: Hewlett-Packard Developmet Company, L.P.
    Inventors: Ruth Bernstein, Ira Cohen
  • Publication number: 20140229768
    Abstract: A method for automated detection of a real IT system problem may include obtaining monitor measurements of metrics associated with activities of a plurality of configuration items of the IT system. The method may also include detecting anomalies in the monitor measurements. The method may further include grouping concurrent anomalies of the detected anomalies corresponding to configuration items of the plurality of configuration items which are topologically linked to be regarded as a system anomaly. The method may further include calculating a significance score for the system anomaly, and determining that the system anomaly relates to a real system problem based on the calculated significance score.
    Type: Application
    Filed: September 21, 2011
    Publication date: August 14, 2014
    Inventors: Ruth Bernstein, Ira Cohen, Eran Samuni
  • Publication number: 20140032552
    Abstract: Defining relationships are described. Defining relationships can include retrieving a number of event notifications that correspond to a number of nodes. Defining relationships can include defining a number of group patterns that correspond to the number of event notifications. Defining relationships can also include grouping the number of nodes into a number of groups that correlate with the number of group patterns, the number of groups defining a number of relationships between the number of nodes. Defining relationships can include assigning a number of weights to the number of relationships between the number of nodes, wherein the number of weights are based on a strength of the number of relationships between the number of nodes.
    Type: Application
    Filed: July 30, 2012
    Publication date: January 30, 2014
    Inventors: Ira Cohen, Ruth Bernstein, Yonatan Ben Simhon
  • Patent number: 8635498
    Abstract: Embodiments of methods and systems for analyzing performance of an application are provided. In that regard, an embodiment of a method for analyzing performance, among others, comprises collecting performance metric data from the application over time; segmenting the performance metric data into time segments representing sets of contiguous time samples which exhibit similar performance metric behavior; determining the presence of an anomaly in a time segment; and correlating the anomalous segment with other data available to the system to determine the cause of the anomaly.
    Type: Grant
    Filed: October 16, 2008
    Date of Patent: January 21, 2014
    Assignee: Hewlett-Packard Development Company, L.P.
    Inventors: Chen Kahana, Ruth Bernstein, Ifat Gavish
  • Publication number: 20130275816
    Abstract: At least one value of abnormal metrics is identified as being an abnormal dimension value. A dominant dimension related to the anomaly is identified based on the identified abnormal dimension value.
    Type: Application
    Filed: April 16, 2012
    Publication date: October 17, 2013
    Inventors: RUTH BERNSTEIN, IRA COHEN
  • Publication number: 20130275812
    Abstract: Methods, systems, and computer-readable media with executable instructions stored thereon for determining root cause are provided. A method for determining root cause can include receiving values for at least one performance metric for each of a plurality of components of an IT system to establish a normal value for each of the performance metrics, receiving an abnormal value that differs from the normal value for at least one of the plurality of components of the IT system, and determining a probability that the at least one of the plurality of components of the IT system is a root cause of the abnormal value.
    Type: Application
    Filed: April 16, 2012
    Publication date: October 17, 2013
    Inventors: Ruth Bernstein, Ira Cohen, Eran Samuni, Keren Gattegno
  • Publication number: 20130080451
    Abstract: A method and system comprise abstracting configuration items (CI) in at least a first anomaly and a second anomaly based on type of CI. Further, CIs are matched of a common type between the first and second anomalies based on a cost function. Additionally, a similarity score is computed for the first and second anomalies based, at least in part, on the cost function of the matched CI's and based on topology of the first and second anomalies.
    Type: Application
    Filed: June 9, 2010
    Publication date: March 28, 2013
    Inventors: Ruth Bernstein, Ira Cohen, Chen Kahana
  • Publication number: 20110276836
    Abstract: Embodiments of methods and systems for analyzing performance of an application are provided. In that regard, an embodiment of a method for analyzing performance, among others, comprises collecting performance metric data from the application over time; segmenting the performance metric data into time segments representing sets of contiguous time samples which exhibit similar performance metric behaviour; determining the presence of an anomaly in a time segment; and correlating the anomalous segment with other data available to the system to determine the cause of the anomaly.
    Type: Application
    Filed: October 16, 2008
    Publication date: November 10, 2011
    Inventors: Chen Kahana, Ruth Bernstein, Ifat Gavish