Intsights Cyber Intelligence Ltd.

Israel

Back to Profile

1-33 of 33 for Intsights Cyber Intelligence Ltd. Sort by
Query
Aggregations
IP Type
        Patent 31
        Trademark 2
Jurisdiction
        United States 30
        Europe 2
        World 1
Date
2026 (YTD) 1
2025 2
2024 5
2023 6
2022 2
See more
IPC Class
H04L 9/40 - Network security protocols 22
G06F 9/54 - Interprogram communication 9
G06N 20/00 - Machine learning 9
H04L 41/14 - Network analysis or design 9
H04L 41/142 - Network analysis or design using statistical or mathematical methods 9
See more
NICE Class
09 - Scientific and electric apparatus and instruments 2
42 - Scientific, technological and industrial services, research and design 2
Status
Pending 5
Registered / In Force 28

1.

AUTOMATED BRAND PROTECTION TECHNIQUES

      
Application Number 19397787
Status Pending
Filing Date 2025-11-21
First Publication Date 2026-03-19
Owner IntSights Cyber Intelligence Ltd. (Israel)
Inventor
  • Ben David, Gal
  • Hozez, Amir
  • Arvatz, Alon
  • Nizan, Guy

Abstract

A method for defending against malicious profiles on the web comprises the steps of: i) inspecting a profile to determine its relevance to a brand that it is desired to protect from malicious activity; ii) determining whether said profile is relevant to said brand; iii) if it is determined that said profile is relevant, analyzing it to determine whether it is legitimate or malicious; and iv) if it is determined that the profile is malicious, assembling proof of its malicious activity and submitting same together with a takedown request to the administrator of the website where the profile was located.

IPC Classes  ?

2.

CYBERATTACK DETECTION USING PROBABILISTIC GRAPHICAL MODELS

      
Application Number 19016989
Status Pending
Filing Date 2025-01-10
First Publication Date 2025-05-08
Owner INTSIGHTS CYBER INTELLIGENCE LTD. (Israel)
Inventor
  • Niv, Nitzan
  • Naor, Gad

Abstract

Various embodiments include systems and methods to implement a security platform providing cyberattack detection. The security platform may, with respect to a cloud compute environment, use audit log data that is associated with a particular domain of operational activity within the cloud compute environment. Based on multiple baseline profiles associated with the operational activity, the security platform may use a probabilistic graph to determine a behavioral anomaly. The security platform may, based on the behavioral anomaly, identify a cyberattack.

IPC Classes  ?

3.

MULTI-BASELINE UNSUPERVISED SECURITY-INCIDENT AND NETWORK BEHAVIORAL ANOMALY DETECTION IN CLOUD-BASED COMPUTE ENVIRONMENTS

      
Application Number 19017058
Status Pending
Filing Date 2025-01-10
First Publication Date 2025-05-08
Owner INTSIGHTS CYBER INTELLIGENCE LTD. (Israel)
Inventor
  • Niv, Nitzan
  • Naor, Gad

Abstract

A method and system for detecting anomalous network activity in a cloud-based compute environment. The method comprises receiving configuration data and network activity observations for a set of virtual entities in the cloud-based compute environment; creating a profile for each virtual entity in the set of virtual entities, when the virtual entity does not already have an associated profile; dynamically updating the virtual entity of a profile with the respective network activity observations of the virtual entity; and determining whether anomalies have been detected.

IPC Classes  ?

  • H04L 41/0893 - Assignment of logical groups to network elements
  • G06F 9/54 - Interprogram communication
  • G06N 5/01 - Dynamic search techniquesHeuristicsDynamic treesBranch-and-bound
  • G06N 20/00 - Machine learning
  • G06Q 30/0251 - Targeted advertisements
  • H04L 9/40 - Network security protocols
  • H04L 41/069 - Management of faults, events, alarms or notifications using logs of notificationsPost-processing of notifications
  • H04L 41/0895 - Configuration of virtualised networks or elements, e.g. virtualised network function or OpenFlow elements
  • H04L 41/14 - Network analysis or design
  • H04L 41/142 - Network analysis or design using statistical or mathematical methods
  • H04L 41/40 - Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks using virtualisation of network functions or resources, e.g. SDN or NFV entities
  • H04L 43/062 - Generation of reports related to network traffic
  • H04L 67/30 - Profiles
  • H04L 67/50 - Network services
  • H04W 12/06 - Authentication

4.

Cyberattack detection using probabilistic graphical models

      
Application Number 18649017
Grant Number 12235901
Status In Force
Filing Date 2024-04-29
First Publication Date 2024-09-26
Grant Date 2025-02-25
Owner INTSIGHTS CYBER INTELLIGENCE LTD. (Israel)
Inventor
  • Niv, Nitzan
  • Naor, Gad

Abstract

Various embodiments include systems and methods to implement a security platform providing cyberattack detection. The security platform may, with respect to a cloud compute environment, use audit log data that is associated with a particular domain of operational activity within the cloud compute environment. Based on multiple baseline profiles associated with the operational activity, the security platform may use a probabilistic graph to determine a behavioral anomaly. The security platform may, based on the behavioral anomaly, identify a cyberattack.

IPC Classes  ?

5.

Multi-baseline unsupervised security-incident and network behavioral anomaly detection in cloud-based compute environments

      
Application Number 18629589
Grant Number 12237979
Status In Force
Filing Date 2024-04-08
First Publication Date 2024-08-01
Grant Date 2025-02-25
Owner INTSIGHTS CYBER INTELLIGENCE LTD. (Israel)
Inventor
  • Niv, Nitzan
  • Naor, Gad

Abstract

A method and system for detecting anomalous network activity in a cloud-based compute environment. The method comprises receiving configuration data and network activity observations for a set of virtual entities in the cloud-based compute environment; creating a profile for each virtual entity in the set of virtual entities, when the virtual entity does not already have an associated profile; dynamically updating the virtual entity of a profile with the respective network activity observations of the virtual entity; and determining whether anomalies have been detected.

IPC Classes  ?

  • H04L 41/142 - Network analysis or design using statistical or mathematical methods
  • G06F 9/54 - Interprogram communication
  • G06N 5/01 - Dynamic search techniquesHeuristicsDynamic treesBranch-and-bound
  • G06N 20/00 - Machine learning
  • G06Q 30/0251 - Targeted advertisements
  • H04L 9/40 - Network security protocols
  • H04L 41/069 - Management of faults, events, alarms or notifications using logs of notificationsPost-processing of notifications
  • H04L 41/14 - Network analysis or design
  • H04L 43/062 - Generation of reports related to network traffic
  • H04L 67/30 - Profiles
  • H04L 67/50 - Network services
  • H04W 12/06 - Authentication

6.

Unsupervised detection of security incidents in a cloud environment

      
Application Number 17979122
Grant Number 12008222
Status In Force
Filing Date 2022-11-02
First Publication Date 2024-06-11
Grant Date 2024-06-11
Owner INTSIGHTS CYBER INTELLIGENCE LTD. (Israel)
Inventor
  • Niv, Nitzan
  • Naor, Gad

Abstract

Various embodiments include systems and methods to implement a security platform providing cyberattack detection. The security platform may, with respect to a cloud compute environment, use audit log data that is associated with a particular domain of operational activity within the cloud compute environment. Based on a domain specific graph representative of factor data and dependencies between factor data, the security platform may determine a behavioral anomaly that is associated with a cyberattack.

IPC Classes  ?

  • G06F 3/0484 - Interaction techniques based on graphical user interfaces [GUI] for the control of specific functions or operations, e.g. selecting or manipulating an object, an image or a displayed text element, setting a parameter value or selecting a range
  • G06F 9/54 - Interprogram communication
  • G06N 7/01 - Probabilistic graphical models, e.g. probabilistic networks
  • G06N 20/00 - Machine learning
  • G06Q 30/0251 - Targeted advertisements
  • H04L 9/40 - Network security protocols
  • H04L 41/14 - Network analysis or design
  • H04L 41/142 - Network analysis or design using statistical or mathematical methods
  • H04L 43/062 - Generation of reports related to network traffic
  • H04L 67/30 - Profiles
  • H04W 12/06 - Authentication

7.

Cyberattack detection using probabilistic graphical models

      
Application Number 17979132
Grant Number 12010127
Status In Force
Filing Date 2022-11-02
First Publication Date 2024-06-11
Grant Date 2024-06-11
Owner INTSIGHTS CYBER INTELLIGENCE LTD. (Israel)
Inventor
  • Niv, Nitzan
  • Naor, Gad

Abstract

Various embodiments include systems and methods to implement a security platform providing cyberattack detection. The security platform may, with respect to a cloud compute environment, use audit log data that is associated with a particular domain of operational activity within the cloud compute environment. Based on multiple baseline profiles associated with the operational activity, the security platform may use a probabilistic graph to determine a behavioral anomaly. The security platform may, based on the behavioral anomaly, identify a cyberattack.

IPC Classes  ?

  • G06F 3/0484 - Interaction techniques based on graphical user interfaces [GUI] for the control of specific functions or operations, e.g. selecting or manipulating an object, an image or a displayed text element, setting a parameter value or selecting a range
  • G06F 9/54 - Interprogram communication
  • G06N 20/00 - Machine learning
  • G06Q 30/0251 - Targeted advertisements
  • H04L 9/40 - Network security protocols
  • H04L 41/14 - Network analysis or design
  • H04L 41/142 - Network analysis or design using statistical or mathematical methods
  • H04L 43/062 - Generation of reports related to network traffic
  • H04L 67/30 - Profiles
  • H04W 12/06 - Authentication

8.

Automated social media-related brand protection

      
Application Number 18467624
Grant Number 12513191
Status In Force
Filing Date 2023-09-14
First Publication Date 2024-01-04
Grant Date 2025-12-30
Owner IntSights Cyber Intelligence Ltd. (Israel)
Inventor
  • Ben David, Gal
  • Hozez, Amir
  • Arvatz, Alon
  • Nizan, Guy

Abstract

A method for defending against malicious profiles on the web, the method including: i) inspecting a profile to determine its relevance to a brand that it is desired to protect from malicious activity; ii) determining whether the profile is relevant to the brand; iii) if it is determined that the profile is relevant, analyzing it to determine whether it is legitimate or malicious; and iv) if it is determined that the profile is malicious, assembling proof of its malicious activity and submitting same together with a takedown request to the administrator of the website where the profile was located.

IPC Classes  ?

9.

Techniques for mitigating leakage of user credentials

      
Application Number 18463738
Grant Number 12489740
Status In Force
Filing Date 2023-09-08
First Publication Date 2023-12-28
Grant Date 2025-12-02
Owner IntSights Cyber Intelligence Ltd. (Israel)
Inventor
  • Ben David, Gal
  • Hozez, Amir
  • Arvatz, Alon
  • Nizan, Guy

Abstract

Systems and methods of mitigating leakage of credentials of a user of a computer network, including monitoring at least one data source to scrape data that is compatible with credential data, applying a machine learning algorithm to the scraped data to identify at least one potential leaked credential, wherein the at least one potential leaked credential is identified using at least one neural network, authenticating the identified at least one potential leaked credential by a database of valid credentials of the computer network, and replacing credentials corresponding to the at least one leaked credential.

IPC Classes  ?

10.

Multi-baseline unsupervised security-incident and network behavioral anomaly detection in cloud-based compute environments

      
Application Number 18446402
Grant Number 11985040
Status In Force
Filing Date 2023-08-08
First Publication Date 2023-11-30
Grant Date 2024-05-14
Owner INTSIGHTS CYBER INTELLIGENCE LTD. (Israel)
Inventor
  • Niv, Nitzan
  • Naor, Gad

Abstract

A method and system for detecting anomalous network activity in a cloud-based compute environment. The method comprises receiving configuration data and network activity observations for a set of virtual entities in the cloud-based compute environment; creating a profile for each virtual entity in the set of virtual entities, when the virtual entity does not already have an associated profile; dynamically updating the virtual entity of a profile with the respective network activity observations of the virtual entity; and determining whether anomalies have been detected.

IPC Classes  ?

  • H04L 41/142 - Network analysis or design using statistical or mathematical methods
  • G06F 9/54 - Interprogram communication
  • G06N 5/01 - Dynamic search techniquesHeuristicsDynamic treesBranch-and-bound
  • G06N 20/00 - Machine learning
  • G06Q 30/0251 - Targeted advertisements
  • H04L 9/40 - Network security protocols
  • H04L 41/069 - Management of faults, events, alarms or notifications using logs of notificationsPost-processing of notifications
  • H04L 41/14 - Network analysis or design
  • H04L 43/062 - Generation of reports related to network traffic
  • H04L 67/30 - Profiles
  • H04L 67/50 - Network services
  • H04W 12/06 - Authentication

11.

SYSTEM AND METHOD FOR DETECTING LEAKED DOCUMENTS ON A COMPUTER NETWORK

      
Application Number 18195863
Status Pending
Filing Date 2023-05-10
First Publication Date 2023-10-05
Owner IntSights Cyber Intelligence Ltd. (Israel)
Inventor
  • Ben David, Gal
  • Hozez, Amir
  • Arvatz, Alon
  • Nizan, Guy
  • Ur, Shmuel

Abstract

A system and a method of obtaining a location of a document on a computer network based on a document property. The method may include: receiving at least one basic marker and an encoding function associated with the document property; generating a search term according to the encoding function, based on the at least one basic marker; providing the search term to at least one search engine and obtaining therefrom one or more search results corresponding, where each search result may include one or more references to locations of documents on the computer network; discovering at least one document having the document property from the one or more search results and obtaining a discovered location of the document on the computer network; and performing at least one rule-based action, according to at least one document property of the discovered document.

IPC Classes  ?

  • G06F 21/55 - Detecting local intrusion or implementing counter-measures
  • H04L 9/40 - Network security protocols
  • G06F 16/14 - Details of searching files based on file metadata
  • G06F 16/953 - Querying, e.g. by the use of web search engines

12.

SYSTEM AND METHOD FOR DETECTING LEAKED DOCUMENTS ON A COMPUTER NETWORK

      
Application Number 18195878
Status Pending
Filing Date 2023-05-10
First Publication Date 2023-09-07
Owner IntSights Cyber Intelligence Ltd. (Israel)
Inventor
  • Ben David, Gal
  • Hozez, Amir
  • Arvatz, Alon
  • Nizan, Guy
  • Ur, Shmuel

Abstract

A system and a method of obtaining a location of a document on a computer network based on a document property. The method may include: receiving at least one basic marker and an encoding function associated with the document property; generating a search term according to the encoding function, based on the at least one basic marker; providing the search term to at least one search engine and obtaining therefrom one or more search results corresponding, where each search result may include one or more references to locations of documents on the computer network; discovering at least one document having the document property from the one or more search results and obtaining a discovered location of the document on the computer network; and performing at least one rule-based action, according to at least one document property of the discovered document.

IPC Classes  ?

  • G06F 21/55 - Detecting local intrusion or implementing counter-measures
  • H04L 9/40 - Network security protocols
  • G06F 16/14 - Details of searching files based on file metadata
  • G06F 16/953 - Querying, e.g. by the use of web search engines

13.

System and method for detection of malicious interactions in a computer network

      
Application Number 18105599
Grant Number 11785044
Status In Force
Filing Date 2023-02-03
First Publication Date 2023-06-08
Grant Date 2023-10-10
Owner IntSights Cyber Intelligence Ltd. (Israel)
Inventor
  • Ben David, Gal
  • Hozez, Amir

Abstract

System and method of detecting malicious interactions in a computer network, the method including generating, by a processor, at least one decoy segment, broadcasting, by the processor, the generated at least one decoy segment in a public database, monitoring, by the processor, communication within the computer network to identify interactions associated with the generated at least one decoy segment, determining, by the processor, at least one indicator of compromise (IOC) for the identified interactions, and blocking communication between the computer network and any computer associated with the determined at least one IOC.

IPC Classes  ?

14.

System and method for blocking phishing attempts in computer networks

      
Application Number 18085493
Grant Number 11750649
Status In Force
Filing Date 2022-12-20
First Publication Date 2023-04-27
Grant Date 2023-09-05
Owner IntSights Cyber Intelligence Ltd. (Israel)
Inventor
  • Ben David, Gal
  • Hozez, Amir
  • Arvatz, Alon
  • Nizan, Guy

Abstract

Systems and methods of blocking phishing attempts in a computer network, including receiving a list of assets of the computer network, wherein each asset is associated with at least one computer network address, generating at least one address permutation on the at least one computer network address of each asset of the computer network, wherein the generated at least one address permutation is different from the address associated with each asset of the computer network, receiving a communication request at a gateway server of the computer network, determining a destination address of the communication request, comparing the determined destination address with the at least one address permutation, and when the determined destination address is the same as at least one address permutation, blocking the communication request at the gateway server.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • H04L 9/40 - Network security protocols

15.

Techniques for mitigating leakage of user credentials

      
Application Number 17836947
Grant Number 11792178
Status In Force
Filing Date 2022-06-09
First Publication Date 2022-10-06
Grant Date 2023-10-17
Owner IntSights Cyber Intelligence Ltd. (Israel)
Inventor
  • Ben David, Gal
  • Hozez, Amir
  • Arvatz, Alon
  • Nizan, Guy

Abstract

Systems and methods of mitigating leakage of credentials of a user of a computer network, including monitoring at least one data source to scrape data that is compatible with credential data, applying a machine learning algorithm to the scraped data to identify at least one potential leaked credential, wherein the at least one potential leaked credential is identified using at least one neural network, authenticating the identified at least one potential leaked credential by a database of valid credentials of the computer network, and replacing credentials corresponding to the at least one leaked credential.

IPC Classes  ?

16.

Multi-baseline unsupervised security-incident and network behavioral anomaly detection in cloud-based compute environments

      
Application Number 17590221
Grant Number 11818014
Status In Force
Filing Date 2022-02-01
First Publication Date 2022-05-19
Grant Date 2023-11-14
Owner INTSIGHTS CYBER INTELLIGENCE LTD. (Israel)
Inventor
  • Niv, Nitzan
  • Naor, Gad

Abstract

A method and system for detecting anomalous network activity in a cloud-based compute environment. The method comprises receiving configuration data and network activity observations for a set of virtual entities in the cloud-based compute environment; creating a profile for each virtual entity in the set of virtual entities, when the virtual entity does not already have an associated profile; dynamically updating the virtual entity of a profile with the respective network activity observations of the virtual entity; and determining whether anomalies have been detected.

IPC Classes  ?

17.

System and method for detecting leaked documents on a computer network

      
Application Number 17323292
Grant Number 11693960
Status In Force
Filing Date 2021-05-18
First Publication Date 2021-09-02
Grant Date 2023-07-04
Owner IntSights Cyber Intelligence Ltd. (Israel)
Inventor
  • Ben David, Gal
  • Hozez, Amir
  • Arvatz, Alon
  • Nizan, Guy
  • Ur, Shmuel

Abstract

A system and a method of obtaining a location of a document on a computer network based on a document property. The method may include: receiving at least one basic marker and an encoding function associated with the document property; generating a search term according to the encoding function, based on the at least one basic marker; providing the search term to at least one search engine and obtaining therefrom one or more search results corresponding, where each search result may include one or more references to locations of documents on the computer network; discovering at least one document having the document property from the one or more search results and obtaining a discovered location of the document on the computer network; and performing at least one rule-based action, according to at least one document property of the discovered document.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • G06F 21/55 - Detecting local intrusion or implementing counter-measures
  • H04L 9/40 - Network security protocols
  • G06F 16/14 - Details of searching files based on file metadata
  • G06F 16/953 - Querying, e.g. by the use of web search engines

18.

Automated social media-related brand protection

      
Application Number 17108193
Grant Number 12052281
Status In Force
Filing Date 2020-12-01
First Publication Date 2021-06-24
Grant Date 2024-07-30
Owner IntSights Cyber Intelligence Ltd. (Israel)
Inventor
  • Ben David, Gal
  • Hozez, Amir
  • Arvatz, Alon
  • Nizan, Guy

Abstract

i) inspecting a profile to determine its relevance to a brand that it is desired to protect from malicious activity; ii) determining whether said profile is relevant to said brand; iii) if it is determined that said profile is relevant, analyzing it to determine whether it is legitimate or malicious; and iv) if it is determined that the profile is malicious, assembling proof of its malicious activity and submitting same together with a takedown request to the administrator of the website where the profile was located.

IPC Classes  ?

19.

System and method for blocking phishing attempts in computer networks

      
Application Number 16770626
Grant Number 11575707
Status In Force
Filing Date 2018-12-18
First Publication Date 2021-06-10
Grant Date 2023-02-07
Owner IntSights Cyber Intelligence Ltd. (Israel)
Inventor
  • Ben David, Gal
  • Hozez, Amir
  • Arvatz, Alon
  • Nizan, Guy

Abstract

Systems and methods of blocking phishing attempts in a computer network, including receiving a list of assets of the computer network, wherein each asset is associated with at least one computer network address, generating at least one address permutation on the at least one computer network address of each asset of the computer network, wherein the generated at least one address permutation is different from the address associated with each asset of the computer network, receiving a communication request at a gateway server of the computer network, determining a destination address of the communication request, comparing the determined destination address with the at least one address permutation, and when the determined destination address is the same as at least one address permutation, blocking the communication request at the gateway server.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • H04L 9/40 - Network security protocols

20.

System and method for automatic mitigation of leaked credentials in computer networks

      
Application Number 16351535
Grant Number 11405374
Status In Force
Filing Date 2019-03-13
First Publication Date 2020-09-17
Grant Date 2022-08-02
Owner IntSights Cyber Intelligence Ltd. (Israel)
Inventor
  • David, Gal Ben
  • Hozez, Amir
  • Arvatz, Alon
  • Nizan, Guy

Abstract

Systems and methods of mitigating leakage of credentials of a user of a computer network, including monitoring at least one data source to scrape data that is compatible with credential data, applying a machine learning algorithm to the scraped data to identify at least one potential leaked credential, wherein the at least one potential leaked credential is identified using at least one neural network, authenticating the identified at least one potential leaked credential by a database of valid credentials of the computer network, and replacing credentials corresponding to the at least one leaked credential.

IPC Classes  ?

21.

Multi-baseline unsupervised security-incident and network behavioral anomaly detection in cloud-based compute environments

      
Application Number 16263322
Grant Number 11425149
Status In Force
Filing Date 2019-01-31
First Publication Date 2020-08-06
Grant Date 2022-08-23
Owner INTSIGHTS CYBER INTELLIGENCE LTD. (Israel)
Inventor
  • Niv, Nitzan
  • Naor, Gad

Abstract

A method and system for detecting anomalous network activity in a cloud-based compute environment. The method comprises receiving configuration data and network activity observations for a set of virtual entities in the cloud-based compute environment; creating a profile for each virtual entity in the set of virtual entities, when the virtual entity does not already have an associated profile; dynamically updating the virtual entity of a profile with the respective network activity observations of the virtual entity; and determining whether anomalies have been detected.

IPC Classes  ?

22.

System and method for detecting leaked documents on a computer network

      
Application Number 16242018
Grant Number 11120129
Status In Force
Filing Date 2019-01-08
First Publication Date 2020-07-09
Grant Date 2021-09-14
Owner IntSights Cyber Intelligence Ltd. (Israel)
Inventor
  • Ben David, Gal
  • Hozez, Amir
  • Arvatz, Alon
  • Nizan, Guy
  • Ur, Shmuel

Abstract

A system and a method of obtaining a location of a document on a computer network based on a document property. The method may include: receiving at least one basic marker and an encoding function associated with the document property; generating a search term according to the encoding function, based on the at least one basic marker; providing the search term to at least one search engine and obtaining therefrom one or more search results corresponding, where each search result may include one or more references to locations of documents on the computer network; discovering at least one document having the document property from the one or more search results and obtaining a discovered location of the document on the computer network; and performing at least one rule-based action, according to at least one document property of the discovered document.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • G06F 21/55 - Detecting local intrusion or implementing counter-measures
  • G06F 16/14 - Details of searching files based on file metadata
  • G06F 16/953 - Querying, e.g. by the use of web search engines

23.

Systems and methods for protecting a computing device against malicious code

      
Application Number 16041795
Grant Number 11200317
Status In Force
Filing Date 2018-07-22
First Publication Date 2020-01-23
Grant Date 2021-12-14
Owner INTSIGHTS CYBER INTELLIGENCE LTD. (Israel)
Inventor
  • Moyal, Omri
  • Breiman, Erez
  • Bobritsky, Eduard

Abstract

There is provided a computer implemented method of vaccination of a computing device against infection by malicious code, comprising: obtaining a vaccination profile including vaccination artifact system calls indicative of a malicious code attempting to identify another instance of the malicious code executing on the computing device prior to the malicious code infecting the computing device, monitoring the computing device for an indication of execution of at least one of the vaccination artifact system calls by the malicious code, and providing a false response to the at least one of the vaccination artifact system calls for emulating an existing infection of the computing device by another instance of the malicious code according to the indication of execution of at least one of the plurality of vaccination artifact system calls, wherein the emulation of the existing infection prevents infection of the computing device by the malicious code.

IPC Classes  ?

  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • G06F 21/53 - Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity, buffer overflow or preventing unwanted data erasure by executing in a restricted environment, e.g. sandbox or secure virtual machine

24.

Systems and methods for protecting a computing device against malicious code

      
Application Number 16041796
Grant Number 10853492
Status In Force
Filing Date 2018-07-22
First Publication Date 2020-01-23
Grant Date 2020-12-01
Owner INTSIGHTS CYBER INTELLIGENCE LTD. (Israel)
Inventor
  • Moyal, Omri
  • Breiman, Erez
  • Bobritsky, Eduard

Abstract

There is provided a computer implemented method of generating a vaccination profile of malicious code for vaccination against other instances of the malicious code, comprising: providing malicious code, analyzing the malicious code to identify at least one vaccination artifact system call indicative of an attempt to identify malicious code executing on a client computing device prior to another instance of the malicious code infecting the client computing device, generating according to the analysis of the malicious code, a vaccination profile including the at least one vaccination artifact system call, and providing the vaccination profile to a plurality of client computing devices for vaccination of the plurality of client computing devices uninfected by the malicious code, wherein an existing infection by the malicious code is emulated based on the vaccination profile for prevention of infection of the plurality of computing devices by another instance of the malicious code.

IPC Classes  ?

  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • G06F 21/53 - Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity, buffer overflow or preventing unwanted data erasure by executing in a restricted environment, e.g. sandbox or secure virtual machine

25.

System and method for detection of malicious interactions in a computer network

      
Application Number 16002065
Grant Number 11611583
Status In Force
Filing Date 2018-06-07
First Publication Date 2019-12-12
Grant Date 2023-03-21
Owner IntSights Cyber Intelligence Ltd. (Israel)
Inventor
  • Ben David, Gal
  • Hozez, Amir

Abstract

System and method of detecting malicious interactions in a computer network, the method including generating, by a processor, at least one decoy segment, broadcasting, by the processor, the generated at least one decoy segment in a public database, monitoring, by the processor, communication within the computer network to identify interactions associated with the generated at least one decoy segment, determining, by the processor, at least one indicator of compromise (IOC) for the identified interactions, and blocking communication between the computer network and any computer associated with the determined at least one IOC.

IPC Classes  ?

26.

System and method for mitigating phishing attacks against a secured computing device

      
Application Number 16243104
Grant Number 10462180
Status In Force
Filing Date 2019-01-09
First Publication Date 2019-10-29
Grant Date 2019-10-29
Owner IntSights Cyber Intelligence Ltd. (Israel)
Inventor
  • Ben David, Gal
  • Hozez, Amir
  • Arvatz, Alon
  • Nizan, Guy

Abstract

A system and a method for mitigating phishing attacks against a secured computing device. The method may include: obtaining at least one first domain name; attributing a registration time stamp (RTS) associated with timing of a registration of the at least one domain name at a domain registrar; and configuring at least one perimeter module to restrict at least one data transmission between the secured computing device and a computing device that is associated with the first domain name, based on the RTS.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol

27.

SYSTEM AND METHOD FOR BLOCKING PHISHING ATTEMPTS IN COMPUTER NETWORKS

      
Application Number IL2018051369
Publication Number 2019/123455
Status In Force
Filing Date 2018-12-18
Publication Date 2019-06-27
Owner INTSIGHTS CYBER INTELLIGENCE LTD. (Israel)
Inventor
  • Ben David, Gal
  • Hozez, Amir
  • Arvatz, Alon
  • Nizan, Guy

Abstract

Systems and methods of blocking phishing attempts in a computer network, including receiving a list of assets of the computer network, wherein each asset is associated with at least one computer network address, generating at least one address permutation on the at least one computer network address of each asset of the computer network, wherein the generated at least one address permutation is different from the address associated with each asset of the computer network, receiving a communication request at a gateway server of the computer network, determining a destination address of the communication request, comparing the determined destination address with the at least one address permutation, and when the determined destination address is the same as at least one address permutation, blocking the communication request at the gateway server.

IPC Classes  ?

  • G06F 21/00 - Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity

28.

Ransomware attack remediation

      
Application Number 15746461
Grant Number 10789361
Status In Force
Filing Date 2017-01-23
First Publication Date 2018-07-26
Grant Date 2020-09-29
Owner INTSIGHTS CYBER INTELLIGENCE LTD. (Israel)
Inventor
  • Breiman, Erez
  • Bobritsky, Eduard
  • Moyal, Omri
  • Migdan, Gil
  • Kamanovsky, Denis

Abstract

A method for processing files as a preemptive measure against a ransomware activity. The method comprises scanning a plurality of file operation requests sent to an operating system (OS) executed on a computing device to detect a guarded file operation request that comprises instructions to process a file managed by a file system used by said OS, delaying an execution of said guarded file operation request, temporarily storing a copy of said file in a backup storage in response to said detection of said guarded file operation request, and stop delaying said execution of said guarded file operation request when said copy is stored in said backup storage.

IPC Classes  ?

  • G06F 21/00 - Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • G06F 11/14 - Error detection or correction of the data by redundancy in operation, e.g. by using different operation sequences leading to the same result
  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • G06F 21/60 - Protecting data

29.

Systems and methods for malware evasion management

      
Application Number 15844762
Grant Number 10311235
Status In Force
Filing Date 2017-12-18
First Publication Date 2018-05-03
Grant Date 2019-06-04
Owner INTSIGHTS CYBER INTELLIGENCE LTD. (Israel)
Inventor
  • Bobritsky, Eduard
  • Breiman, Erez
  • Moyal, Omri

Abstract

A method for emulating at least one resource in a host computer to a querying hosted code. The method comprises monitoring a plurality of operating system (OS) queries received from a plurality of code executed on a monitored computing unit, the plurality of OS queries are designated to an OS of the monitored computing unit, detecting among the plurality of OS queries at least one query for receiving at least one characteristic of at least one resource of the monitored computing unit among the plurality of OS queries, the at least one query is received from querying code of the plurality of code, preparing a response of the OS to the at least one query, the response comprising a false indication at least one false characteristic of the at least one resource, and sending the response to the querying code in response to the at least one query.

IPC Classes  ?

  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • G06F 16/245 - Query processing

30.

INTSIGHTS

      
Application Number 017871580
Status Registered
Filing Date 2018-03-09
Registration Date 2018-07-03
Owner INTSIGHTS CYBER INTELLIGENCE LTD. (Israel)
NICE Classes  ?
  • 09 - Scientific and electric apparatus and instruments
  • 42 - Scientific, technological and industrial services, research and design

Goods & Services

Computer software for inspecting electronic files to detect and prevent computer security attacks, computer and email viruses, spam, spyware, adware and malware; computer software for use in controlling, managing, auditing and analyzing data access and usage; computer hardware and computer software in the field of internet and network security; computer software for protecting and securing computer systems and networks; software for ensuring the security of electronic mail. Computer consultation in the field of computer security; design and development of electronic data security systems; providing online, non-downloadable software for inspecting electronic files to detect and prevent computer security attacks, computer and email viruses, spam, spyware, adware and malware; research in the field of intelligence and security technology; computer services, namely, on-line scanning, detecting, quarantining and eliminating of viruses, worms, trojans, spyware, adware, malware and unauthorized data and programs on computers and electronic devices; providing online, non-downloadable software for protecting and securing computer systems and networks; providing computer and information technology security services; computer virus protection services.

31.

INTSIGHTS

      
Application Number 017871289
Status Registered
Filing Date 2018-03-08
Registration Date 2018-06-30
Owner INTSIGHTS CYBER INTELLIGENCE LTD. (Israel)
NICE Classes  ?
  • 09 - Scientific and electric apparatus and instruments
  • 42 - Scientific, technological and industrial services, research and design

Goods & Services

Computer software for inspecting electronic files to detect and prevent computer security attacks, computer and email viruses, spam, spyware, adware and malware; computer software for use in controlling, managing, auditing and analyzing data access and usage; computer hardware and computer software in the field of internet and network security; computer software for protecting and securing computer systems and networks; software for ensuring the security of electronic mail. Computer consultation in the field of computer security; design and development of electronic data security systems; providing online, non-downloadable software for inspecting electronic files to detect and prevent computer security attacks, computer and email viruses, spam, spyware, adware and malware; research in the field of intelligence and security technology; computer services, namely, on-line scanning, detecting, quarantining and eliminating of viruses, worms, trojans, spyware, adware, malware and unauthorized data and programs on computers and electronic devices; providing online, non-downloadable software for protecting and securing computer systems and networks; providing computer and information technology security services; computer virus protection services.

32.

Systems and methods for malware evasion management

      
Application Number 14639191
Grant Number 09846775
Status In Force
Filing Date 2015-03-05
First Publication Date 2016-09-08
Grant Date 2017-12-19
Owner INTSIGHTS CYBER INTELLIGENCE LTD. (Israel)
Inventor
  • Bobritsky, Eduard
  • Breiman, Erez
  • Moyal, Omri

Abstract

A method for emulating at least one resource in a host computer to a querying hosted code. The method comprises monitoring a plurality of operating system (OS) queries received from a plurality of code executed on a monitored computing unit, the plurality of OS queries are designated to an OS of the monitored computing unit, detecting among the plurality of OS queries at least one query for receiving at least one characteristic of at least one resource of the monitored computing unit among the plurality of OS queries, the at least one query is received from querying code of the plurality of code, preparing a response of the OS to the at least one query, the response comprising a false indication at least one false characteristic of the at least one resource, and sending the response to the querying code in response to the at least one query.

IPC Classes  ?

  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements
  • G06F 17/30 - Information retrieval; Database structures therefor

33.

Method and system for handling malware

      
Application Number 14914040
Grant Number 10230757
Status In Force
Filing Date 2014-08-27
First Publication Date 2016-07-21
Grant Date 2019-03-12
Owner INTSIGHTS CYBER INTELLIGENCE LTD. (Israel)
Inventor Bobritsky, Eduard

Abstract

Systems, methods, and software products prevent malware attacks on networks, which include endpoint devices, by providing an environment to the endpoint device which simulates an environment, for example, a security environment, where malware is known to refrain from executing.

IPC Classes  ?

  • H04L 29/06 - Communication control; Communication processing characterised by a protocol
  • G06F 21/56 - Computer malware detection or handling, e.g. anti-virus arrangements