-
公开(公告)号:US09870480B2
公开(公告)日:2018-01-16
申请号:US12861059
申请日:2010-08-23
Applicant: Yakov Faitelson , Ohad Korkus , Ophir Kretzer-Katzir , David Bass
Inventor: Yakov Faitelson , Ohad Korkus , Ophir Kretzer-Katzir , David Bass
CPC classification number: G06F21/6218 , G06F21/6263 , G06F2221/2101 , G06F2221/2141 , G06F2221/2149 , G06Q10/103 , H04L63/105
Abstract: A system for automatically replacing a user security group-based computer security policy by a computer security policy based at least partially on actual access, including a learned access permissions subsystem operative to learn current access permissions of users to network objects in an enterprise computer environment and to provide an indication of which users are members of which user security groups having access permissions to which network objects, a learned actual access subsystem operative to learn actual access history of users in the enterprise to the network objects and to provide indications of which users have had actual access to which network objects, and a computer security policy administration subsystem, receiving indications from the learned access permission subsystem and the learned actual access subsystem and being operative to automatically replace pre-selected user-security group-based access permissions with at least partially actual access-based access permissions without disrupting access to network objects.
-
公开(公告)号:US09747459B2
公开(公告)日:2017-08-29
申请号:US13437004
申请日:2012-04-02
Applicant: Yakov Faitelson , Ohad Korkus , David Bass
Inventor: Yakov Faitelson , Ohad Korkus , David Bass
CPC classification number: G06F21/604
Abstract: A method for requesting access rights for an object of a computerized system comprising installing in the computerized system a code that associates an object with an owner of the object, thereby enabling to automatically request access rights for the object from an owner of the object, and an apparatus for performing the same.
-
3.
公开(公告)号:US08782027B2
公开(公告)日:2014-07-15
申请号:US13356658
申请日:2012-01-24
Applicant: Yakov Faitelson , Ohad Korkus , David Bass , Yzhar Kaysar , Doron Goldstein , Oren David
Inventor: Yakov Faitelson , Ohad Korkus , David Bass , Yzhar Kaysar , Doron Goldstein , Oren David
IPC: G06F17/30
CPC classification number: G06F17/30144 , G06F3/0614 , G06F3/0653 , G06F3/0673 , G06F17/30091
Abstract: A computerized method and apparatus for distinguishing between false positive read events and true positive events of reading a file, comprising determining an amount of date read from the file, in case the amount of data exceeds a threshold generating a true positive read event, otherwise generating a false positive read event in case a decision condition is met, and an apparatus to carry out the same.
Abstract translation: 一种用于区分读取文件的假正读事件和真正正事件的计算机化方法和装置,包括在数据量超过产生真正正读事件的阈值的情况下确定从文件读取的日期量,否则生成 在满足判定条件的情况下的假阳性读取事件,以及执行该判定条件的装置。
-
4.
公开(公告)号:US20130191358A1
公开(公告)日:2013-07-25
申请号:US13356658
申请日:2012-01-24
Applicant: Yakov FAITELSON , Ohad Korkus , David Bass , Yzhar Kaysar , Doron Goldstein , Oren David
Inventor: Yakov FAITELSON , Ohad Korkus , David Bass , Yzhar Kaysar , Doron Goldstein , Oren David
IPC: G06F17/30
CPC classification number: G06F17/30144 , G06F3/0614 , G06F3/0653 , G06F3/0673 , G06F17/30091
Abstract: A computerized method and apparatus for distinguishing between false positive read events and true positive events of reading a file, comprising determining an amount of date read from the file, in case the amount of data exceeds a threshold generating a true positive read event, otherwise generating a false positive read event in case a decision condition is met, and an apparatus to carry out the same.
Abstract translation: 一种用于区分读取文件的假正读事件和真正正事件的计算机化方法和装置,包括在数据量超过产生真正正读事件的阈值的情况下确定从文件读取的日期量,否则生成 在满足判定条件的情况下的假阳性读取事件,以及执行该判定条件的装置。
-
公开(公告)号:US11151515B2
公开(公告)日:2021-10-19
申请号:US13562711
申请日:2012-07-31
Applicant: Yakov Faitelson , Ohad Korkus , Ophir Kretzer-Katzir , David Bass
Inventor: Yakov Faitelson , Ohad Korkus , Ophir Kretzer-Katzir , David Bass
IPC: G06Q10/10
Abstract: A computer-implemented method for controlling email distribution list membership in an enterprise email system, including the steps of monitoring and collecting continuously updated information regarding access to email distribution lists of an email system by members of the email distribution lists, ascertaining that a particular member of at least one of the email distribution lists has not accessed the at least one of the email distribution lists for a predetermined period of time, and responsive to the ascertaining, at least one of recommending revoking membership of the particular member to the at least one of the email distribution lists and automatically revoking membership of the particular member to the at least one of the email distribution lists.
-
公开(公告)号:US10037358B2
公开(公告)日:2018-07-31
申请号:US13384459
申请日:2011-05-26
Applicant: Yakov Faitelson , Ohad Korkus , Ophir Kretzer-Katzir , David Bass
Inventor: Yakov Faitelson , Ohad Korkus , Ophir Kretzer-Katzir , David Bass
CPC classification number: G06F16/2457 , G06F16/36 , G06F16/93 , G06F16/9535 , G06F21/6227 , G06F2221/2141
Abstract: A method for managing data in an enterprise by identifying data of interest from among a multiplicity of data elements in an enterprise, the method including characterizing data of interest at least by at least one non-content based data identifier thereof and at least one access metric thereof, the at least one access metric being selected from data access permissions and actual data access history and selecting data of interest by considering only data elements from among the multiplicity of data elements which have the at least one non-content based data identifier thereof and the at least one access metric thereof.
-
7.
公开(公告)号:US09286316B2
公开(公告)日:2016-03-15
申请号:US13439276
申请日:2012-04-04
Applicant: Yakov Faitelson , Ohad Korkus , David Bass , Yzhar Kaysar
Inventor: Yakov Faitelson , Ohad Korkus , David Bass , Yzhar Kaysar
IPC: G06F15/173 , G06F7/00 , G06F17/30 , H04L29/08
CPC classification number: G06F17/30174 , G06F17/30194 , G06F17/30203 , G06F17/30566 , G06F17/30575 , G06F17/30864 , H04L67/1004
Abstract: An enterprise data collection system including at least one database for receiving over a network and storing data collected from data resources at a plurality of physical sites located at disparate locations, a plurality of remotely synchronizable probes (RSPs) located at the plurality of physical sites, the remotely synchronizable probes (RSPs) performing at least one of the following data collection functions: real time event collection, file system crawling for data structure and permissions, data content analysis, data indexing, data tagging and event triggered alerts, and at least one RSP manager located remotely from at least one of the plurality of remotely synchronizable probes and being operative to govern the operation of and orchestrate data collection and transmission by the plurality of remotely synchronizable probes (RSPs).
Abstract translation: 一种企业数据收集系统,包括至少一个数据库,用于通过网络接收并存储从位于不同位置的多个物理站点处的数据资源收集的数据,位于多个物理站点处的多个可远程同步的探测器(RSP) 执行以下数据收集功能中的至少一个的远程可同步探测(RSP):实时事件收集,用于数据结构和许可的文件系统爬行,数据内容分析,数据索引,数据标记和事件触发警报,以及至少一个 RSP管理器远离多个远程可同步探测器中的至少一个,并且可操作地控制多个远程可同步探测器(RSP)的操作和协调数据收集和传输。
-
公开(公告)号:US09177167B2
公开(公告)日:2015-11-03
申请号:US13384452
申请日:2011-05-26
Applicant: Yakov Faitelson , Ohad Korkus , Ophir Kretzer-Katzir , David Bass
Inventor: Yakov Faitelson , Ohad Korkus , Ophir Kretzer-Katzir , David Bass
CPC classification number: G06F21/6218 , G06F17/30038 , G06F17/30082 , G06F17/301 , G06F21/604 , G06F2221/2101 , G06F2221/2141 , G06Q10/0633
Abstract: An information technology management system for use in enterprise data management including a metadata supply subsystem which receives metadata from a network, an access permissions management subsystem for managing access permissions to data elements in the network and an access permissions management operation implementation subsystem which automatically governs the operation of the access permissions management subsystem, the access permissions management operation implementation subsystem having at least one of first, second, third and fourth modes of operation. The first mode of operation includes operating the access permissions management subsystem, the second mode of operation includes simulating the operation of the access permissions management subsystem, the third mode of operation included providing a report of proposed changes in access permissions and the fourth mode of operation includes providing an actionable report of multiple steps in implementation of proposed changes in access permissions to data elements for approval.
Abstract translation: 一种用于企业数据管理的信息技术管理系统,包括从网络接收元数据的元数据供应子系统,用于管理对网络中的数据元素的访问权限的访问权限管理子系统,以及自动管理网络中的数据元素的访问权限管理操作实现子系统 访问权限管理子系统的操作,具有第一,第二,第三和第四操作模式中的至少一个的访问许可管理操作实现子系统。 第一操作模式包括操作访问许可管理子系统,第二操作模式包括模拟访问许可管理子系统的操作,第三操作模式包括提供访问权限中提出的改变的报告和第四操作模式 包括提供一个可执行的报告,其中包括多个步骤来实施对数据元素的访问权限的建议更改以供批准。
-
公开(公告)号:US09147180B2
公开(公告)日:2015-09-29
申请号:US12861953
申请日:2010-08-24
Applicant: Ohad Korkus , Yakov Faitelson , Ophir Kretzer-Katzir , David Bass
Inventor: Ohad Korkus , Yakov Faitelson , Ophir Kretzer-Katzir , David Bass
CPC classification number: H04L51/22 , G06F21/128 , G06Q10/10 , G06Q10/107 , H04L51/046 , H04L51/14 , H04L63/102
Abstract: An enterprise email governance system including an enterprise-wide email communication item events monitoring subsystem providing at least near real time indications of email communication item events and an enterprise-wide email communication item events storage subsystem receiving inputs from the monitoring subsystem and providing at least near real time user accessibility to the email communication item events.
Abstract translation: 一种企业电子邮件治理系统,包括企业级电子邮件通信项目事件监控子系统,其提供电子邮件通信项目事件的至少近实时指示,以及企业范围的电子邮件通信项目事件存储子系统,其从所述监视子系统接收输入并提供至少近 电子邮件通信项目事件的实时用户可访问性。
-
公开(公告)号:US08578507B2
公开(公告)日:2013-11-05
申请号:US12814807
申请日:2010-06-14
Applicant: Yakov Faitelson , Ohad Korkus , Ophir Kretzer-Katzir , David Bass
Inventor: Yakov Faitelson , Ohad Korkus , Ophir Kretzer-Katzir , David Bass
IPC: G06F17/30 , G06F21/00 , G06F15/173
CPC classification number: H04L63/104 , G06F21/604 , G06F2221/2141 , G06Q10/10 , H04L63/101 , H04L63/105 , H04L63/20
Abstract: A system for operating an enterprise computer network including multiple network objects, said system comprising monitoring and collection functionality for obtaining continuously updated information regarding at least one of access permissions and actual usage of said network objects, and entitlement review by owner functionality operative to present to at least one owner of at least one network object a visually sensible indication of authorization status including a specific indication of users which were not yet authorized by said at least one owner of said at least one network object.
-
-
-
-
-
-
-
-
-