Patents by Inventor Joseph Kubilus

Joseph Kubilus has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 9961103
    Abstract: A network-based appliance includes a mechanism to intercept, decrypt and inspect secure network traffic flowing over SSL/TLS between a client and a server. The mechanism responds to detection of a session initiation request message from the client, the message being received following establishment of a TCP connection between the client and server. The mechanism responds by holding the session initiation request message, preferably by creating a fake socket to a local process, and then diverting the request message over that socket. The TCP connection is then terminated, and the mechanism initiates a new session in initiation request message, all while the original session initiation request message continues to be held. The server responds with its server certificate, which is then used by the mechanism to generate a new server certificate. The new server certificate is then returned to the requesting client as the response to the session initiation request message.
    Type: Grant
    Filed: October 28, 2014
    Date of Patent: May 1, 2018
    Assignee: International Business Machines Corporation
    Inventors: Ronald Becker Williams, Paul Coccoli, John William Court, Gregory Lyle Galloway, Matthew Joseph Kubilus, Steven Ashley Mazur, Joseph Karl Vossen
  • Patent number: 9774631
    Abstract: A network-based appliance includes a mechanism to enable the appliance to extract itself from man-in-the-middle (MITM) processing during a client-server handshake and without interrupting that connection. The mechanism enables the appliance to decide (e.g., based on a rule match against a received server certificate) to stop performing MITM during the handshake and thus to de-insert itself transparently, i.e., without interfering or signaling to either end of the session that this operation is occurring. Once the connection is abandoned in the manner, the appliance ignores additional traffic flow and thus can free up processing resources (CPU, memory, and the like) that would otherwise be required to decrypt the connection (even if no further inspection or rewrite processing would be expected to occur).
    Type: Grant
    Filed: October 29, 2014
    Date of Patent: September 26, 2017
    Assignee: International Business Machines Corporation
    Inventors: Steven Ashley Mazur, Matthew Joseph Kubilus, Jr.
  • Publication number: 20160127414
    Abstract: A network-based appliance includes a mechanism to enable the appliance to extract itself from man-in-the-middle (MITM) processing during a client-server handshake and without interrupting that connection. The mechanism enables the appliance to decide (e.g., based on a rule match against a received server certificate) to stop performing MITM during the handshake and thus to de-insert itself transparently, i.e., without interfering or signaling to either end of the session that this operation is occurring. Once the connection is abandoned in the manner, the appliance ignores additional traffic flow and thus can free up processing resources (CPU, memory, and the like) that would otherwise be required to decrypt the connection (even if no further inspection or rewrite processing would be expected to occur).
    Type: Application
    Filed: October 29, 2014
    Publication date: May 5, 2016
    Inventors: Steven Ashley Mazur, Matthew Joseph Kubilus, JR.
  • Publication number: 20160119374
    Abstract: A network-based appliance includes a mechanism to intercept, decrypt and inspect secure network traffic flowing over SSL/TLS between a client and a server. The mechanism responds to detection of a session initiation request message from the client, the message being received following establishment of a TCP connection between the client and server. The mechanism responds by holding the session initiation request message, preferably by creating a fake socket to a local process, and then diverting the request message over that socket. The TCP connection is then terminated, and the mechanism initiates a new session in initiation request message, all while the original session initiation request message continues to be held. The server responds with its server certificate, which is then used by the mechanism to generate a new server certificate. The new server certificate is then returned to the requesting client as the response to the session initiation request message.
    Type: Application
    Filed: October 28, 2014
    Publication date: April 28, 2016
    Inventors: Ronald Becker Williams, Paul Coccoli, John William Court, Gregory Lyle Galloway, Matthew Joseph Kubilus, Steven Ashley Mazur, Joseph Karl Vossen
  • Publication number: 20080003677
    Abstract: Disclosed is a cervico-vaginal tissue equivalent comprised of vaginal epithelial cells and immune cells, cultured at the air-liquid interface. The tissue equivalent is capable of being infected with a sexually transmitted pathogen such as a virus (e.g., HIV), a bacteria, a helminthic parasite, or a fungus. The tissue equivalent is also capable of undergoing an allergic-type reaction or an irritant-type reaction. The tissue equivalent is characterized as having nucleated basal layer cells and nucleated suprabasal layer cells, and further as having cell layers external to the suprabasal layer progressively increasing in glycogen content and progressively decreasing in nuclei content. Immune cells of the tissue equivalent are primarily located in the basal and suprabasal layers. Also disclosed are methods for producing the tissue equivalent.
    Type: Application
    Filed: June 24, 2005
    Publication date: January 3, 2008
    Applicant: MatTek Corporation
    Inventors: Mitchell Klausner, Seyoum Ayehunie, Joseph Kubilus
  • Patent number: 6943021
    Abstract: Disclosed is a cervico-vaginal tissue equivalent comprised of vaginal epithelial cells and immune cells, cultured at the air-liquid interface. The tissue equivalent is capable of being infected with a sexually transmitted pathogen such as a virus (e.g., HIV), a bacteria, a helminthic parasite, or a fungus. The tissue equivalent is also capable of undergoing an allergic-type reaction or an irritant-type reaction. The tissue equivalent is characterized as having nucleated basal layer cells and nucleated suprabasal layer cells, and further as having cell layers external to the suprabasal layer progressively increasing in glycogen content and progressively decreasing in nuclei content. Immune cells of the tissue equivalent are primarily located in the basal and suprabasal layers. Also disclosed are methods for producing the tissue equivalent.
    Type: Grant
    Filed: June 7, 2002
    Date of Patent: September 13, 2005
    Assignee: MatTek Corporation
    Inventors: Mitchell Klausner, Seyoum Ayehunie, Joseph Kubilus
  • Publication number: 20030228686
    Abstract: Disclosed is a cervico-vaginal tissue equivalent comprised of vaginal epithelial cells and immune cells, cultured at the air-liquid interface. The tissue equivalent is capable of being infected with a sexually transmitted pathogen such as a virus (e.g., HIV), a bacteria, a helminthic parasite, or a fungus. The tissue equivalent is also capable of undergoing an allergic-type reaction or an irritant-type reaction. The tissue equivalent is characterized as having nucleated basal layer cells and nucleated suprabasal layer cells, and further as having cell layers external to the suprabasal layer progressively increasing in glycogen content and progressively decreasing in nuclei content. Immune cells of the tissue equivalent are primarily located in the basal and suprabasal layers. Also disclosed are methods for producing the tissue equivalent.
    Type: Application
    Filed: June 7, 2002
    Publication date: December 11, 2003
    Applicant: MatTek Corporation
    Inventors: Mitchell Klausner, Seyoum Ayehunie, Joseph Kubilus