Patents by Inventor Jeffrey M. Napper

Jeffrey M. Napper has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20260148124
    Abstract: In one embodiment, a method includes accessing a plurality of requirements for an agentic application, inferring an execution flow corresponding to the agentic application based on the plurality of requirements using a pre-trained first model, where the execution flow includes a sequence of blocks connected by a graph from a start block to an end block, wherein each of the blocks is associated with an input, an output, and a functional intent, identifying subsets of the blocks that require corresponding efficacy measurement among the blocks belonging to the execution flow, wherein the subsets of the blocks comprise at least each individual block, associating a corresponding efficacy analysis function measuring efficacy with each of the subsets of the blocks, causing the agentic application to be deployed, receiving feedback generated based on operations of the deployed agentic application, and retraining the pre-trained first model using at least the received feedback.
    Type: Application
    Filed: November 25, 2024
    Publication date: May 28, 2026
    Inventors: Jeffrey M. Napper, Marc Scibelli, Hendrikus G. P. Bosch, Pete Rai, Guillaume Sauvage de Saint Marc
  • Publication number: 20260148231
    Abstract: In an embodiment, a method includes intercepting, by a trust processor, a transaction interaction communicated between an artificial intelligence (AI) agent and a service. The transaction interaction includes a series of requests associated with a transaction. The method also includes receiving, by the trust processor and from a user device, a first response to a request for the user device to provide a verification to a commitment to the transaction. The method further includes determining, by the trust processor, whether to allow the transaction to proceed to the service based on the first response.
    Type: Application
    Filed: July 1, 2025
    Publication date: May 28, 2026
    Inventors: Hendrikus G. P. Bosch, Alessandro Duminuco, Jeffrey M. Napper
  • Publication number: 20260147647
    Abstract: In an embodiment, a method includes sharing, via a publication-subscription (pub-sub) bus, an unaddressed message between a plurality of agents. The unaddressed message includes a program counter pointing to a first instruction of a program written in a programming language. The method also includes determining, by each respective agent of the plurality of agents, whether the respective agent can perform the instruction and, in response to a first agent of the plurality of agents determining that the first agent can perform the instruction, consuming, by the first agent, the unaddressed message. The method further includes removing, by the first agent, the unaddressed message from the bus, performing, by the first agent, the instruction, adding, by the first agent, one to the program counter, and posting, by the first agent, a response to the pub-sub bus for further processing of the program.
    Type: Application
    Filed: July 1, 2025
    Publication date: May 28, 2026
    Inventors: Hendrikus G. P. Bosch, Jeffrey M. Napper, Alessandro Duminuco, Alex Jauch, Andre Jean Marie Surcouf, Guillaume Sauvage De Saint Marc, Jodee A. Varney, Frank Brockners
  • Patent number: 12639447
    Abstract: A system and a method to map attack paths in a visualization interface may include storing in a memory asset inventory indicating application assets, attack vector parameters configured to indicate vulnerabilities of one or more of the application assets, and asset mapping information. A processor may determine multiple vulnerable assets in the application assets based at least in part upon the attack vector parameters. Further, the processor may obtain security parameters from a security framework indicating one or more attack techniques, associate each of the vulnerable assets to one or more of the security parameters, and generate a visual interface showing the vulnerable assets and the security parameters. The processor may determine an attack path connecting the vulnerable assets based at least in part upon the asset mapping information, and map the attack path to the application layers and the security parameters in the visual interface.
    Type: Grant
    Filed: June 6, 2023
    Date of Patent: May 26, 2026
    Assignee: Cisco Technology, Inc.
    Inventors: Jeffrey M. Napper, Hendrikus G. P. Bosch, Jean Diaconu, Marcelo Yannuzzi, Alessandro Duminuco, Guillaume Sauvage De Saint Marc, Marc Scibelli
  • Publication number: 20260100963
    Abstract: In one embodiment, a method includes ingesting security tool findings associated with an application and identifying events associated with the application. The method also includes comparing the security tool findings and the events against known attack paths and determining partial attack path matches between the security tool findings and the events and the known attack paths. The method further includes performing a risk analysis of the partial attack path matches and prioritizing the partial attack path matches based on the risk analysis.
    Type: Application
    Filed: December 11, 2025
    Publication date: April 9, 2026
    Inventors: Hendrikus G. P. Bosch, Jeffrey M. Napper, Willem Jonker, Stefano Simonetto
  • Patent number: 12506753
    Abstract: In one embodiment, a method includes ingesting security tool findings associated with an application and identifying events associated with the application. The method also includes comparing the security tool findings and the events against known attack paths and determining partial attack path matches between the security tool findings and the events and the known attack paths. The method further includes performing a risk analysis of the partial attack path matches and prioritizing the partial attack path matches based on the risk analysis.
    Type: Grant
    Filed: July 11, 2023
    Date of Patent: December 23, 2025
    Assignee: CISCO TECHNOLOGY, INC.
    Inventors: Hendrikus G. P. Bosch, Jeffrey M. Napper, Willem Jonker, Stefano Simonetto
  • Publication number: 20250023887
    Abstract: In one embodiment, a method includes ingesting security tool findings associated with an application and identifying events associated with the application. The method also includes comparing the security tool findings and the events against known attack paths and determining partial attack path matches between the security tool findings and the events and the known attack paths. The method further includes performing a risk analysis of the partial attack path matches and prioritizing the partial attack path matches based on the risk analysis.
    Type: Application
    Filed: July 11, 2023
    Publication date: January 16, 2025
    Inventors: Hendrikus G. P. Bosch, Jeffrey M. Napper, Willem Jonker, Stefano Simonetto
  • Publication number: 20240273203
    Abstract: In one embodiment, a method for detecting an unknown attack vector, by a system, includes receiving a marked span that has been flagged for inspection. The method further includes conducting a root cause analysis to determine if the marked span should be classified as an attack. In response to a determination that the marked span should be classified as an attack, the method further includes determining whether the marked span engaged with data corresponding to one or more application services defining the marked span. The method further includes designating the data corresponding to the one or more application services as compromised in response to a determination that the marked span did engage with said data.
    Type: Application
    Filed: May 31, 2023
    Publication date: August 15, 2024
    Inventors: Mirko Raca, Marcelo Yannuzzi, Jeffrey M. Napper, Hendrikus G. P. Bosch
  • Publication number: 20240273187
    Abstract: In one embodiment, a method for storing auditable metadata, by a system, includes receiving incoming signals communicated from at least one application service to a first pod associated with a user space of a node. The method further includes extracting metadata associated with data provided by the received incoming signals. The method further includes receiving outgoing signals communicated from the first pod to an external entity, wherein the incoming signals and the outgoing signals are received by a listener module. The method further includes comparing the incoming signals to the outgoing signals to detect a variation and determining that the data has been transmitted to the external entity based on a determination that there is no detected variation from the comparison between the incoming signals and the outgoing signals.
    Type: Application
    Filed: May 31, 2023
    Publication date: August 15, 2024
    Inventors: Marcelo Yannuzzi, Jean Diaconu, Jeffrey M. Napper, Herve Muyal, Hendrikus G. P. Bosch
  • Publication number: 20240265112
    Abstract: A system and a method to map attack paths in a visualization interface may include storing in a memory asset inventory indicating application assets, attack vector parameters configured to indicate vulnerabilities of one or more of the application assets, and asset mapping information. A processor may determine multiple vulnerable assets in the application assets based at least in part upon the attack vector parameters. Further, the processor may obtain security parameters from a security framework indicating one or more attack techniques, associate each of the vulnerable assets to one or more of the security parameters, and generate a visual interface showing the vulnerable assets and the security parameters. The processor may determine an attack path connecting the vulnerable assets based at least in part upon the asset mapping information, and map the attack path to the application layers and the security parameters in the visual interface.
    Type: Application
    Filed: June 6, 2023
    Publication date: August 8, 2024
    Inventors: Jeffrey M. Napper, Hendrikus G. P. Bosch, Jean Diaconu, Marcelo Yannuzzi, Alessandro Duminuco, Guillaume Sauvage De Saint Marc, Marc Scibelli
  • Publication number: 20240265113
    Abstract: A system and a method to determine attack paths to application assets may include storing in a memory asset inventory indicating multiple application assets, multiple attack vector parameters configured to indicate vulnerabilities of one or more of the application assets, and asset mapping information configured to associate each of the application assets to one or more of the application layers. A processor may determine multiple vulnerable assets in the application assets based at least in part upon the attack vector parameters. Further, the processor may determine feasibility parameters that indicate a likelihood of the attack path to occur in the system, generate a visual interface showing the vulnerable assets, determine an attack path connecting the vulnerable assets based at least in part upon the asset mapping information, and map the attack path to the application layers in the visual interface based at least in part upon the feasibility parameters.
    Type: Application
    Filed: June 6, 2023
    Publication date: August 8, 2024
    Inventors: Jeffrey M. Napper, Hendrikus G. P. Bosch, Jean Diaconu, Marcelo Yannuzzi, Alessandro Duminuco
  • Publication number: 20240231973
    Abstract: In one embodiment, a method includes generating an application stack. The application stack includes an application logic module. The method also includes embedding a service mesh module into the application stack. The method further includes managing, by the service mesh module, security of a network packet while maintaining separation of memory regions between the application logic module and the service mesh module.
    Type: Application
    Filed: April 28, 2023
    Publication date: July 11, 2024
    Inventors: Hendrikus G. P. Bosch, Jeffrey M. Napper, Zsolt Varga, Nándor István Krácser, Krisztián Gacsal
  • Patent number: 12033010
    Abstract: In one embodiment, a method includes generating an application stack. The application stack includes an application logic module. The method also includes embedding a service mesh module into the application stack. The method further includes managing, by the service mesh module, security of a network packet while maintaining separation of memory regions between the application logic module and the service mesh module.
    Type: Grant
    Filed: April 28, 2023
    Date of Patent: July 9, 2024
    Assignee: CISCO TECHNOLOGY, INC.
    Inventors: Hendrikus G. P. Bosch, Jeffrey M. Napper, Zsolt Varga, Nándor István Krácser, Krisztián Gacsal
  • Publication number: 20240134725
    Abstract: In one embodiment, a method includes generating an application stack. The application stack includes an application logic module. The method also includes embedding a service mesh module into the application stack. The method further includes managing, by the service mesh module, security of a network packet while maintaining separation of memory regions between the application logic module and the service mesh module.
    Type: Application
    Filed: April 27, 2023
    Publication date: April 25, 2024
    Inventors: Hendrikus G. P. Bosch, Jeffrey M. Napper, Zsolt Varga, Nándor István Krácser, Krisztián Gacsal