Patents by Inventor Ronald Mraz

Ronald Mraz has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 10218586
    Abstract: A system is disclosed for monitoring a channel passing information which includes an identifying designation. A channel monitor is coupled to the channel and configured to provide on an output all information passing on the channel. A manifest engine is coupled to the channel monitor to receive the information passing on the channel and to an operator console to receive an information manifest table. The information manifest table contains at least one identifying designation. The manifest engine compares the information received with the information in the information manifest table and only provides on the output that information having an identifying designation that matches an identifying designation included within the information manifest table. A storage server is coupled to the manifest engine and configured to receive and store the information provided from the manifest engine.
    Type: Grant
    Filed: January 23, 2013
    Date of Patent: February 26, 2019
    Assignee: Owl Cyber Defense Solutions, LLC
    Inventors: Ronald Mraz, Gabriel Silberman
  • Patent number: 10171422
    Abstract: A configurable packet filtering system includes a packet filter configured to receive packets or groups of packets on an input. The packet filter compares predetermined portions of the received packets with information or criteria stored in a filter configuration file, and, if the information at the predetermined portions of the packets or groups of packets matches the information or criteria stored in the filter configuration file, forwards the packets or groups of packets on an output. The configurable packet filtering system also includes a filter configuration interface which is configured to receive a file on an input, to verify that the received file conforms to a predetermined specification, and, if the received file conforms to the predetermined specification, to replace the filter configuration file with the received file.
    Type: Grant
    Filed: April 14, 2016
    Date of Patent: January 1, 2019
    Assignee: Owl Cyber Defense Solutions, LLC
    Inventors: Ronald Mraz, Robert M. Zucker
  • Patent number: 9894083
    Abstract: A system for providing a secure video display using a one-way data link. An input interface for receives a video stream signal. The one-way data link has an input node coupled to receive the input video stream signal and an output node. A processing system is coupled to the output node of the one-way data link and is configured to run a predetermined operating system. In an embodiment, a video display software program operates within the predetermined operating system to process the video stream signal received from the output node of the one-way data link and to provide an output signal for viewing on a display coupled to the processing system. Optionally, the video display program operates within a virtual operating system running within the predetermined operating system. In other embodiments, the video display program may process a video stream signal containing a plurality of different video programs.
    Type: Grant
    Filed: October 9, 2014
    Date of Patent: February 13, 2018
    Assignee: Owl Cyber Defense Solutions, LLC
    Inventors: Ronald Mraz, Jeffrey Menoher, Andrew Holmes
  • Patent number: 9880869
    Abstract: Three embodiments of one-way cross-domain systems for transferring information from a client in a first security domain to a server in a second separate security domain are disclosed. In addition, three embodiments of bilateral cross-domain systems for transferring first information from a client in a first security domain to a server in a second separate security domain and second information from the server in the second separate security domain to the client in the first security domain are also disclosed. Each of the one-way and bilateral cross-domain systems is based upon a single computer server which employs a number of virtual machines to implement send and receive servers. The single computer server also implements one (for the one-way cross-domain systems) or two (for the bilateral cross-domain systems) virtual one-way data links in either virtual machines or within the hypervisor portion of the operating system.
    Type: Grant
    Filed: May 14, 2015
    Date of Patent: January 30, 2018
    Assignee: Owl Cyber Defense Solutions, LLC
    Inventors: Ronald Mraz, Steven Staubly, Michael M. Tsao
  • Patent number: 9853918
    Abstract: Two embodiments of a one-way network interface card are disclosed, a transmit-only version and a receive-only version. A network controller mounted on the circuit card is coupled to the host computer via a host computer interface. A first processor is coupled to a network interface of the network controller. A second processor has a separate network interface for communicating with a remote computer. A one-way link is coupled between the first processor and the second processor. For the transmit-only embodiment, the one-way link only allows information to be transferred from the first processor to the second processor, and thus information may only pass from the host computer to the remote computer. For the receive-only embodiment, the one-way link only allows information to be transferred from the second processor to the first processor, and thus information may only pass from the remote computer to the host computer.
    Type: Grant
    Filed: March 24, 2015
    Date of Patent: December 26, 2017
    Assignee: Owl Cyber Defense Solutions, LLC
    Inventors: Ronald Mraz, Robert M Zucker, Steven Staubly
  • Publication number: 20170302625
    Abstract: A configurable packet filtering system includes a packet filter configured to receive packets or groups of packets on an input. The packet filter compares predetermined portions of the received packets with information or criteria stored in a filter configuration file, and, if the information at the predetermined portions of the packets or groups of packets matches the information or criteria stored in the filter configuration file, forwards the packets or groups of packets on an output. The configurable packet filtering system also includes a filter configuration interface which is configured to receive a file on an input, to verify that the received file conforms to a predetermined specification, and, if the received file conforms to the predetermined specification, to replace the filter configuration file with the received file.
    Type: Application
    Filed: April 14, 2016
    Publication date: October 19, 2017
    Inventors: Ronald Mraz, Robert M. Zucker
  • Patent number: 9736121
    Abstract: A manifest transfer engine for a one-way file transfer system is disclosed. The manifest transfer engine comprises a send side, a receive side, and a one-way data link enforcing unidirectional data flow from the send side to the receive side. The send side receives and stores a file manifest table from an administrator server. The send side also receives a file from a user and compares it with the file manifest table. Transfer of the file to the receive side via the one-way data link is allowed only when there is a match between the file and the file manifest table. In an alternative embodiment, the receive side instead receives and stores the file manifest table from the administrator server and compares it with the file received from the send side via the one-way data link to determine whether to allow transfer of the file.
    Type: Grant
    Filed: January 23, 2013
    Date of Patent: August 15, 2017
    Assignee: OWL Cyber Defense Solutions, LLC
    Inventors: Ronald Mraz, James Hope
  • Patent number: 9712543
    Abstract: A system for monitoring the status of one or more networks and/or of devices coupled to each of the one or more networks. Status monitoring applications are associated with the networks and/or devices. The status monitoring applications output a respective status log file containing information about the system status of the associated network or device. In one embodiment, the system status is derived from the Windows Event Log. The status monitoring applications are coupled to a remote receive module via a one-way data link or a firewall. The remote receive module receives the log files and processes the log files to either identify any unauthorized status conditions identified therein or to generate a cumulative log file consisting of events occurring over a predetermined time interval.
    Type: Grant
    Filed: January 23, 2013
    Date of Patent: July 18, 2017
    Assignee: Owl Cyber Defense Solutions, LLP
    Inventors: Ronald Mraz, Frederick Clarke
  • Patent number: 9680794
    Abstract: A system for transmitting ArchestrA information from a first network in a first security domain to a second network in a second security domain. A first stand-alone server within the first security domain retrieves information via the first network from a first ArchestrA Galaxy and/or from a first historian in the first security domain and forwards the retrieved information to a send server coupled to the first network. The send server forwards the received information received to a receive server via a one-way data link. The receive server receives the information from the send server and forwards the received information to a second stand-alone server via the second network. The second stand-alone server receives the information from the receive server and forwards the information to a second ArchestrA Galaxy and/or to a second historian in the second security domain.
    Type: Grant
    Filed: September 4, 2013
    Date of Patent: June 13, 2017
    Assignee: Owl Computing Technologies, LLC
    Inventors: John Curry, Ronald Mraz
  • Patent number: 9678921
    Abstract: A method and system for monitoring data transfers over a one-way data link from a send node to a receive node. A send log file monitoring and transmitting module associated with the send node on a first server outputs a send log file containing information about data sent by the send node. A receive log file monitoring and transmitting module associated with the receive node on a second server outputs a receive log file containing information about data received by the receive node. A reconciliation module on a third server receives the send log file and the receive log file and identifies any data transfer errors by comparing the send log file with the receive log file. A web server is coupled to the reconciliation module to provide user access to the identified data transfer errors.
    Type: Grant
    Filed: March 21, 2012
    Date of Patent: June 13, 2017
    Assignee: Owl Computing Technologies, LLC
    Inventors: Frederick Clarke, Ronald Mraz
  • Patent number: 9641499
    Abstract: A system for transferring information from a first PI server coupled to a first network to a second PI server coupled to a second network. The system includes a source platform coupled to the first network and in communication with the first PI server, a receive platform coupled to the second network and in communication with the second PI server, and a one-way data link coupling the source platform to the receive platform. The source platform is configured to read transfer configuration information from the first PI server and to dynamically modify the transfer parameters based thereon. The receive platform is configured to, if there is changed database record configuration information, continually store a current predefined portion of the historical information in memory without transferring such information to the second PI server until a user, via a user interface, authorizes the release of such information to the second PI server.
    Type: Grant
    Filed: July 12, 2013
    Date of Patent: May 2, 2017
    Assignee: Owl Computing Technologies, LLC
    Inventors: John Curry, Ronald Mraz
  • Patent number: 9596245
    Abstract: A one-way interface for a network device which secures status registers therein from unauthorized changes. The interface includes a first server, a one-way data link and a second server. The first server is coupled to the status registers to read information stored therein. The first server reads the information from the status registers and transmits the information on an output. The one-way data link has an input coupled to the output of the first server and an output. The second server has an input coupled to the output of the one-way data link and an output coupled to a network. The second server receives the information from the first server via the one-way data link. The second server transmits the information on the output to a predetermined network destination and/or provides a user interface for providing access to the information via the network.
    Type: Grant
    Filed: April 4, 2013
    Date of Patent: March 14, 2017
    Assignee: Owl Computing Technologies, Inc.
    Inventors: Ronald Mraz, Gabriel Silberman
  • Patent number: 9575987
    Abstract: A system for assuredly copying information from a reference database to a remote database. A send server is coupled to a first network. A receive server is coupled to a second network. A one-way data link provides unidirectional transfer of information from the send server to the receive server. A monitor application iteratively forwards update files including sequence information to the send server. An update application receives each update file and updates the remote database based therein. The update files are also sequentially stored in the send server in groups and each group is sent to the receive server and stored in memory. If an update file is not received in proper sequential order, the receive server stops sending update files in the current group and instead reads the missing update file and subsequent update files in the current group from memory and forwards such files to the update application.
    Type: Grant
    Filed: December 11, 2014
    Date of Patent: February 21, 2017
    Assignee: Owl Computing Technologies, Inc.
    Inventors: Ronald Mraz, Robert M Zucker
  • Publication number: 20160285786
    Abstract: Two embodiments of a one-way network interface card are disclosed, a transmit-only version and a receive-only version. A network controller mounted on the circuit card is coupled to the host computer via a host computer interface. A first processor is coupled to a network interface of the network controller. A second processor has a separate network interface for communicating with a remote computer. A one-way link is coupled between the first processor and the second processor. For the transmit-only embodiment, the one-way link only allows information to be transferred from the first processor to the second processor, and thus information may only pass from the host computer to the remote computer. For the receive-only embodiment, the one-way link only allows information to be transferred from the second processor to the first processor, and thus information may only pass from the remote computer to the host computer.
    Type: Application
    Filed: March 24, 2015
    Publication date: September 29, 2016
    Inventors: Ronald Mraz, Robert M. Zucker, Steven Staubly
  • Patent number: 9436825
    Abstract: A system is disclosed for assuring the integrity of file segments. A first server has an associated file repository storing a plurality of files and transfers a file segment on an output upon request. A second server also has an associated file repository and receives and stores the file segment in the associated file repository. The second server identifies if there are additional segments of the same file in the associated file repository and processes the received file segment together with the additional identified file segments to identify the presence of malware. Finally, the second server transfers the received file segment on an output as a scanned file segment only if no malware is identified. A third server has an associated file repository and is configured to receive and store the scanned file segments in the associated file repository and to transfer a received scanned file segment to a client.
    Type: Grant
    Filed: March 25, 2014
    Date of Patent: September 6, 2016
    Assignee: Owl Computing Technologies, Inc.
    Inventors: Ronald Mraz, Gabriel Silberman
  • Publication number: 20160205215
    Abstract: Three embodiments of one-way cross-domain systems for transferring information from a client in a first security domain to a server in a second separate security domain are disclosed. In addition, three embodiments of bilateral cross-domain systems for transferring first information from a client in a first security domain to a server in a second separate security domain and second information from the server in the second separate security domain to the client in the first security domain are also disclosed. Each of the one-way and bilateral cross-domain systems is based upon a single computer server which employs a number of virtual machines to implement send and receive servers. The single computer server also implements one (for the one-way cross-domain systems) or two (for the bilateral cross-domain systems) virtual one-way data links in either virtual machines or within the hypervisor portion of the operating system.
    Type: Application
    Filed: May 14, 2015
    Publication date: July 14, 2016
    Inventors: Ronald Mraz, Steven Staubly, Michael M. Tsao
  • Patent number: 9380064
    Abstract: A system is disclosed for monitoring the status of a website operating on a host and for remedying any identified problems. A first platform is coupled to the host for monitoring the website and periodically transmits status information about the website. A second platform is coupled to the first platform for periodically receiving the status information about the at least one feature. The second platform is configured to compare the received status information with a copy of the website and based thereon determine if the website has been compromised. The second platform is further configured to output an alert signal after determining that the website has been compromised. A third platform is coupled to the second platform and separately coupled to the host computer. The third platform is configured to receive the alert signal from the second platform and to forward the alert signal to the host computer.
    Type: Grant
    Filed: July 12, 2013
    Date of Patent: June 28, 2016
    Assignee: Owl Computing Technologies, Inc.
    Inventors: Ronald Mraz, Gabriel Silberman
  • Patent number: 9380023
    Abstract: A cross-domain system for transferring files from a client to a server. A first server in the first network domain receives and stores files from the client via the first network. The received files are processed based on predetermined instructions stored in an associated file. The processed received files are transmitted to a second server via a one-way data link. The second server in the second network domain receives and stores the processed received files. The received files are further processed based on predetermined instructions stored in an associated file. The further processed received files are transmitted to the server via the second network. The two associated files are stored in permanent memory with security policies which prevent the files from disrupting operation of the first and second servers, respectively. The security policies allow the associated files to be overwritten to update the processing performed by the associated server.
    Type: Grant
    Filed: September 4, 2013
    Date of Patent: June 28, 2016
    Assignee: Owl Computing Technologies, Inc.
    Inventors: Ronald Mraz, James Hope
  • Patent number: 9311329
    Abstract: A system for assuring the integrity of information files includes a first server, a manifest transfer engine and a second server. The first server stores information files and an associated manifest file containing a manifest entry for each stored information file. The manifest transfer engine receives the manifest file and the information files from the first server on a predetermined basis. The manifest transfer engine compares an identifying characteristic of each received information file with the manifest entries in the manifest file and, when there is a match, transfers the associated information file on the output as an authenticated information file.
    Type: Grant
    Filed: June 5, 2014
    Date of Patent: April 12, 2016
    Assignee: Owl Computing Technologies, Inc.
    Inventors: Ronald Mraz, Gabriel Silberman
  • Patent number: 9306953
    Abstract: A system for securely transferring commands to a recipient device. An access interface allows a user to enter a command for the recipient device. The access interface only allows the user to enter commands within a subset of commands associated with a role assigned to the user. The control interface receives information, i.e., the command entered by the user and the associated user role, from the access interface. The control interface outputs, to the manifest engine, the information and a manifest table which identifies each role and the subset of commands associated with each role. The manifest engine compares the information with the contents of the received manifest table, and, if the command entered by the user corresponds to a command within the set of commands associated with the role assigned to the user, forwards the command to the recipient device.
    Type: Grant
    Filed: February 19, 2013
    Date of Patent: April 5, 2016
    Assignee: Owl Computing Technologies, Inc.
    Inventors: Ronald Mraz, Gabriel Silberman