The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 11, 2019

Filed:

Dec. 19, 2017
Applicant:

Varonis Systems, Inc., New York, NY (US);

Inventors:

Yakov Faitelson, Elkana, IL;

Ohad Korkus, Herzilia, IL;

Ophir Kretzer-Katzir, Reut, IL;

David Bass, Carmei Yoseph, IL;

Assignee:

VARONIS SYSTEMS, INC., New York, NY (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/62 (2013.01); G06Q 10/10 (2012.01); H04L 29/06 (2006.01);
U.S. Cl.
CPC ...
G06F 21/6218 (2013.01); G06F 21/6263 (2013.01); G06Q 10/103 (2013.01); H04L 63/105 (2013.01); G06F 2221/2101 (2013.01); G06F 2221/2141 (2013.01); G06F 2221/2149 (2013.01);
Abstract

A system for automatically replacing a user security group-based computer security policy by a computer security policy based at least partially on actual access, including a learned access permissions subsystem operative to learn current access permissions of users to network objects in an enterprise computer environment and to provide an indication of which users are members of which user security groups having access permissions to which network objects, a learned actual access subsystem operative to learn actual access history of users in the enterprise to the network objects and to provide indications of which users have had actual access to which network objects, and a computer security policy administration subsystem, receiving indications from the learned access permission subsystem and the learned actual access subsystem and being operative to automatically replace pre-selected user-security group-based access permissions with at least partially actual access-based access permissions without disrupting access to network objects.


Find Patent Forward Citations

Loading…