Patents by Inventor Shlomo Yona
Shlomo Yona has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 11140178Abstract: A method and system for collecting information on responses and their interpretation on a client device that requests access to a server. A request to access the server is received. If there was a response by the server for this request, then the response is being intercepted and is being injected with a client side language script to be executed by the requesting client side device. Information is collected at the server side from the execution of the injected client side language script by the client device.Type: GrantFiled: September 16, 2010Date of Patent: October 5, 2021Assignee: F5 Networks, Inc.Inventors: Shlomo Yona, Ron Talmor
-
Patent number: 11122067Abstract: Methods, non-transitory computer readable media, anomaly detection apparatuses, and network traffic management systems that generate, based on the application of one or more models and for a first flow associated with a received first set of network traffic, one or more likelihood scores and at least one flow score based on the likelihood scores. One or more of the one or more models are associated with one or more browsing patterns for a web application to which the first set of network traffic is directed. A determination is made when the flow score exceeds a threshold. A mitigation action is initiated, based on a stored policy, with respect to the first set of network traffic, when the determining indicates that the flow score exceeds the established threshold.Type: GrantFiled: August 7, 2019Date of Patent: September 14, 2021Assignee: F5 NETWORKS, INC.Inventors: Shlomo Yona, Ron Talmor, Itsik Mantin, Yaniv Shemesh
-
Patent number: 10834110Abstract: A method, non-transitory computer readable medium, and device includes monitoring a session layer and transport layer network traffic data received from a plurality of client computing devices and plurality of servers. A plurality of network traffic anomaly threshold values and a plurality of server health anomaly threshold values for the monitored session layer and the transport layer network traffic data are estimated. Whether a plurality of current network traffic anomaly values and a plurality of current server health anomaly values for the monitored network traffic data exceeds each of the corresponding estimated plurality of network traffic anomaly threshold values and the estimated plurality of server health anomaly threshold values, and whether the current plurality of network traffic anomaly values and the current plurality of server health anomaly values are not a false anomaly is determined. A mitigation action is initiated based on the determination.Type: GrantFiled: December 18, 2016Date of Patent: November 10, 2020Assignee: F5 Networks, Inc.Inventors: Sergei Edelstein, Michael Kapelevich, Shlomo Yona, Ron Talmor
-
Patent number: 10505818Abstract: A method, non-transitory computer readable medium, and health analysis apparatus that monitors network traffic exchanged with a plurality of server devices in a server pool to obtain signal data regarding a plurality of signals associated with the network traffic. A determination is made when there is a sever health anomaly for one or more of the server devices based on an application of a server health prediction model to the signal data. The server health prediction model includes a plurality of predictive health targets each based at least in part on historical signal data for one or more of the signals and having an associated threshold value. A mitigation action is initiated when the determining indicates there is a sever health anomaly for one or more of the server devices.Type: GrantFiled: May 4, 2016Date of Patent: December 10, 2019Assignee: F5 Networks. Inc.Inventors: Shlomo Yona, Maydan Wienreb, Michael Kapelevich, Peter Finkelshtein
-
Publication number: 20190364067Abstract: Methods, non-transitory computer readable media, anomaly detection apparatuses, and network traffic management systems that generate, based on the application of one or more models and for a first flow associated with a received first set of network traffic, one or more likelihood scores and at least one flow score based on the likelihood scores. One or more of the one or more models are associated with one or more browsing patterns for a web application to which the first set of network traffic is directed. A determination is made when the flow score exceeds a threshold. A mitigation action is initiated, based on a stored policy, with respect to the first set of network traffic, when the determining indicates that the flow score exceeds the established threshold.Type: ApplicationFiled: August 7, 2019Publication date: November 28, 2019Inventors: Shlomo Yona, Ron Talmor, Itsik Mantin, Yaniv Shemesh
-
Patent number: 10432652Abstract: Methods, non-transitory computer readable media, anomaly detection apparatuses, and network traffic management systems that generate, based on the application of one or more models and for a first flow associated with a received first set of network traffic, one or more likelihood scores and at least one flow score based on the likelihood scores. One or more of the one or more models are associated with one or more browsing patterns for a web application to which the first set of network traffic is directed. A determination is made when the flow score exceeds a threshold. A mitigation action is initiated, based on a stored policy, with respect to the first set of network traffic, when the determining indicates that the flow score exceeds the established threshold.Type: GrantFiled: September 20, 2017Date of Patent: October 1, 2019Assignee: F5 Networks, Inc.Inventors: Shlomo Yona, Ron Talmor, Itsik Mantin, Yaniv Shemesh
-
Patent number: 10129277Abstract: A method, non-transitory computer readable medium, and anomaly detection apparatus that monitors network traffic exchanged with a plurality of client devices and a plurality of server devices to obtain client-side signal data for a plurality of client-side signals and server-side signal data for a plurality of server-side signals. A determination is made when a server health anomaly or a network traffic anomaly is a false positive based at least in part on a comparison of at least a portion of the client-side signal data or at least a portion of the server-side signal data to a historical scoreboard database comprising historical data regarding one or more historical network traffic or server health anomalies. A mitigation action is initiated when the determining indicates that one or more of the server health anomaly or network traffic anomaly is not a false positive.Type: GrantFiled: May 4, 2016Date of Patent: November 13, 2018Assignee: F5 Networks, Inc.Inventors: Sergei Edelstein, Shlomo Yona
-
Patent number: 10122740Abstract: A method, non-transitory computer readable medium, and network security apparatus that monitors received network traffic to obtain signal data for signals associated with the network traffic in accordance with a stored configuration. A model and configuration update(s) are generated and the stored configuration is updated based on the configuration update(s). The model includes a threshold for at least one of the signals. A determination is made when there is an anomaly in the network traffic based on the application of the model to the signal data or a match of at least a portion of the signal data to an anomalous traffic pattern received from a centralized analytic server computing device. A mitigation action is initiated, when the determining indicates that there is an anomaly in the network traffic. Accordingly, this technology facilitates dynamic and adaptive network traffic analysis and anomaly detection including improvements thereto independent of human intervention.Type: GrantFiled: April 25, 2016Date of Patent: November 6, 2018Assignee: F5 Networks, Inc.Inventors: Peter Finkelshtein, Shlomo Yona
-
Publication number: 20170034210Abstract: A system and method for preventing web scraping which includes receiving a request between a web client and a web server for the web client to receive web content. A client side language script is injected into a response to be sent to the requesting web client, wherein the client side language script contains an event listener to detect a keystroke and/or a mouse movement at the web client. Information is collected from the client side language script relating to whether the keystroke and/or the mouse movement were detected. The web client is selectively allowed to access the web server to receive the web content based on the collected information.Type: ApplicationFiled: May 5, 2016Publication date: February 2, 2017Inventors: Ron Talmor, Shlomo Yona, Orit Margalit, Beni Serfaty
-
Patent number: 9558164Abstract: A method and system for use of XML Schema in conjunction with XML Schema aware applications on a SOAP message including a request with a method defined by a WSDL document. A WSDL document is converted offline to XML Schema. A SOAP message containing a request is received. An XML Schema aware operation is performed on the SOAP message based on previously determined XML Schema derived from the WSDL document.Type: GrantFiled: January 15, 2009Date of Patent: January 31, 2017Assignee: F5 Networks, Inc.Inventors: Richard Sevrinsky, Shlomo Yona
-
Patent number: 9420049Abstract: A system and method for preventing web scraping which includes receiving a request between a web client and a web server for the web client to receive web content. A client side language script is injected into a response to be sent to the requesting web client, wherein the client side language script contains an event listener to detect a keystroke and/or a mouse movement at the web client. Information is collected from the client side language script relating to whether the keystroke and/or the mouse movement were detected. The web client is selectively allowed to access the web server to receive the web content based on the collected information.Type: GrantFiled: June 30, 2010Date of Patent: August 16, 2016Assignee: F5 Networks, Inc.Inventors: Ron Talmor, Shlomo YĆ³na, Orit Margalit, Beni Serfaty
-
Patent number: 8566444Abstract: A method and system for checking data against a plurality of rules simultaneously. A data string having keywords in the data string is received. All of the keywords in the data string are simultaneously examined against rule keywords using for example, a finite state machine constructed by the Aho-Corasick algorithm. The rule keyword represents at least one rule of the plurality of rules. It is determined which of the plurality of rules are satisfied by the data string based on whether each keyword matches the rule keywords. Such rules may be used for application such as negative security policies.Type: GrantFiled: October 30, 2008Date of Patent: October 22, 2013Assignee: F5 Networks, Inc.Inventor: Shlomo Yona