Patents by Inventor Carla Marceau

Carla Marceau has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 8458805
    Abstract: A forensic device allows a user to remotely interrogate a target computing device in order to collect and analyze computer evidence that may be stored on the target computing device. The forensic device acquires the computer evidence from the target computing device and filters the computer evidence using an application-specific system-level privilege profile that describes the aggregate exercise of system-level privileges by a plurality of software application instances executing throughout an enterprise. The forensic device presents a user interface through which the remote user views the filtered computer evidence acquired from the target computing device. In this manner, forensic device allows the user to filter the collected computer evidence to data that is likely to have forensic relevance.
    Type: Grant
    Filed: May 20, 2009
    Date of Patent: June 4, 2013
    Assignee: Architecture Technology Corporation
    Inventors: Frank Adelstein, Carla Marceau
  • Patent number: 8015211
    Abstract: A peer-to-peer (P2P) networking system is disclosed that provides a large, persistent object repository with the ability to easily scale to significant size. Data security is provided using a distributed object data access mechanism to grant access to data objects to authorized users. Data objects stored within the object repository are provided a plurality of security options including plain text data, objects, encrypted data objects, and secure, secret sharing data objects. A data object query processing component permits users to locate requested information within the P2P networking system.
    Type: Grant
    Filed: October 1, 2004
    Date of Patent: September 6, 2011
    Assignee: Architecture Technology Corporation
    Inventors: Carla Marceau, Matthew A. Stillerman
  • Patent number: 7908281
    Abstract: This disclosure describes techniques of dynamically assembling and utilizing a pedigree of a resource. A pedigree of a resource is a set of statements that describe a provenance of the resource. As described herein, a set of one or more servers may host context objects that contain the statements that make up the pedigree of the resource. In order to obtain the pedigree of the resource, a context assembly device may send queries to the servers for context objects that are likely to contain statements in the pedigree of the resource. After receiving context objects from the servers in response to the queries, the context assembly device may query the statements in the received context objects in order to identify, among the statements in the context objects, the statements that constitute the pedigree of the resource. The dynamically assembled pedigree may then be used in a variety of ways.
    Type: Grant
    Filed: November 20, 2007
    Date of Patent: March 15, 2011
    Assignee: Architecture Technology Corporation
    Inventors: Carla Marceau, Matthew A. Stillerman, David Rosenthal, Marisa Gioioso
  • Patent number: 7818804
    Abstract: A system is described for dynamically generating an application-specific, system-level privilege profile that describes the aggregate exercise of system-level privileges by a plurality of software application instances. In particular, the system includes a plurality of client computing devices for capturing empirical information relating to the exercise of privileges by the plurality of software application instances executing on top of a plurality of instances of a platforms residing within the plurality of client devices. The plurality of client devices each uploads the empirical information to an EPP server, which is also included within the system. The empirical privilege profiler system dynamically generates the profile based the empirical information. In this way, the system may facilitate adherence to the Principle of Least Privilege by revealing system-level privilege use by an application, monitoring of system-level privilege use, and detection of system intrusions.
    Type: Grant
    Filed: July 31, 2006
    Date of Patent: October 19, 2010
    Assignee: Architecture Technology Corporation
    Inventor: Carla Marceau
  • Publication number: 20090288164
    Abstract: A forensic device allows a user to remotely interrogate a target computing device in order to collect and analyze computer evidence that may be stored on the target computing device. The forensic device acquires the computer evidence from the target computing device and filters the computer evidence using an application-specific system-level privilege profile that describes the aggregate exercise of system-level privileges by a plurality of software application instances executing throughout an enterprise. The forensic device presents a user interface through which the remote user views the filtered computer evidence acquired from the target computing device. In this manner, forensic device allows the user to filter the collected computer evidence to data that is likely to have forensic relevance.
    Type: Application
    Filed: May 20, 2009
    Publication date: November 19, 2009
    Inventors: Frank Adelstein, Carla Marceau
  • Publication number: 20080120281
    Abstract: This disclosure describes techniques of dynamically assembling and utilizing a pedigree of a resource. A pedigree of a resource is a set of statements that describe a provenance of the resource. As described herein, a set of one or more servers may host context objects that contain the statements that make up the pedigree of the resource. In order to obtain the pedigree of the resource, a context assembly device may send queries to the servers for context objects that are likely to contain statements in the pedigree of the resource. After receiving context objects from the servers in response to the queries, the context assembly device may query the statements in the received context objects in order to identify, among the statements in the context objects, the statements that constitute the pedigree of the resource. The dynamically assembled pedigree may then be used in a variety of ways.
    Type: Application
    Filed: November 20, 2007
    Publication date: May 22, 2008
    Applicant: Architecture Technology Corporation
    Inventors: Carla Marceau, Matthew A. Stillerman, David Rosenthal, Marisa Gioioso
  • Publication number: 20080047010
    Abstract: A system is described for dynamically generating an application-specific, system-level privilege profile that describes the aggregate exercise of system-level privileges by a plurality of software application instances. In particular, the system includes a plurality of client computing devices for capturing empirical information relating to the exercise of privileges by the plurality of software application instances executing on top of a plurality of instances of a platforms residing within the plurality of client devices. The plurality of client devices each uploads the empirical information to an EPP server, which is also included within the system. The empirical privilege profiler system dynamically generates the profile based the empirical information. In this way, the system may facilitate adherence to the Principle of Least Privilege by revealing system-level privilege use by an application, monitoring of system-level privilege use, and detection of system intrusions.
    Type: Application
    Filed: July 31, 2006
    Publication date: February 21, 2008
    Applicant: Architecture Technology Corporation
    Inventor: Carla Marceau
  • Patent number: 7272854
    Abstract: In general, the invention is directed to techniques for preventing or otherwise reducing the effects of network attacks, such as Denial of Service (DoS) attacks, on applications that use messaging services. In particular, the invention may be effective for publish/subscribe messaging services and queuing messaging services. The techniques utilize destination aliasing, a form of channel partitioning, in which each messaging service client associated with a messaging service is assigned a unique alias for each topic that the messaging service client requests service. The aliases may be used for monitoring traffic originating from particular clients, defending applications from network attacks, and preventing resumption of an attack by an attacking client.
    Type: Grant
    Filed: June 30, 2003
    Date of Patent: September 18, 2007
    Assignee: Architecture Technology Corporation
    Inventors: Carla Marceau, Kevin S. Millikin, Ranga S. Ramanujan
  • Publication number: 20050240591
    Abstract: A peer-to-peer (P2P) networking system is disclosed that provides a large, persistent object repository with the ability to easily scale to significant size. Data security is provided using a distributed object data access mechanism to grant access to data objects to authorized users. Data objects stored within the object repository are provided a plurality of security options including plain text data, objects, encrypted data objects, and secure, secret sharing data objects. A data object query processing component permits users to locate requested information within the P2P networking system.
    Type: Application
    Filed: October 1, 2004
    Publication date: October 27, 2005
    Inventors: Carla Marceau, Matthew Stillerman
  • Publication number: 20050010753
    Abstract: In general, the invention is directed to techniques for preventing or otherwise reducing the effects of network attacks, such as Denial of Service (DoS) attacks, on applications that use messaging services. In particular, the invention may be effective for publish/subscribe messaging services and queuing messaging services. The techniques utilize destination aliasing, a form of channel partitioning, in which each messaging service client associated with a messaging service is assigned a unique alias for each topic that the messaging service client requests service. The aliases may be used for monitoring traffic originating from particular clients, defending applications from network attacks, and preventing resumption of an attack by an attacking client.
    Type: Application
    Filed: June 30, 2003
    Publication date: January 13, 2005
    Inventors: Carla Marceau, Kevin Millikin, Ranga Ramanujan