Patents by Inventor Ryan Daniel SCHILCHER

Ryan Daniel SCHILCHER has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 12695603
    Abstract: Techniques for detected reuse of a public key of a public/private cryptographic key pair within a cloud environment are disclosed. A database maintained within a cloud environment is accessed, the database storing a plurality of public keys. Each public key has a corresponding attribute, and the database further stores a plurality of attributes corresponding to the plurality of public keys. Each public key is associated with either (i) a corresponding user account of a corresponding tenancy of the cloud environment or (ii) a compute instance hosted within a corresponding tenancy of the cloud environment. A number of times a first public key or a first attribute corresponding to the first public key occurring within the database is determined. Responsive to the number of times being equal to or greater than a threshold number, the first public key is tagged as being reused for at least the threshold number of times.
    Type: Grant
    Filed: July 30, 2024
    Date of Patent: July 28, 2026
    Assignee: Oracle International Corporation
    Inventors: Peter Martin Hanily, Ryan Daniel Schilcher, Christopher Robert Baker, Jonathan Philip Taimanglo
  • Patent number: 12694125
    Abstract: Techniques for detecting inter-tenancy exfiltration of data in a cloud environment are disclosed. A log that includes information associated with receipt of a service message at a gateway within a cloud environment is accessed. Based on the log, (i) originating information of the service message (such as identification of an originating tenancy of the service message) and (ii) target information of the service message (such as identification of a target tenancy of the service message) are determined. The originating information and the target information are compared. A mismatch between the originating information of the service message and the target information of the service message is detected. In response to the detected mismatch between the originating information of the service message and the target information of the service message, information indicative of the detected mismatch is caused to be presented at a user interface.
    Type: Grant
    Filed: September 24, 2024
    Date of Patent: July 28, 2026
    Assignee: Oracle International Corporation
    Inventors: Peter Martin Hanily, Ryan Daniel Schilcher, Christopher Robert Baker, Jonathan Philip Taimanglo
  • Patent number: 12621314
    Abstract: Cyber-security techniques are described for monitoring a cloud environment and identifying potential problems, including malicious threats, to the monitored cloud environment using operational telemetry. Techniques are described for monitoring and collecting data related to reverse or recursive DNS (rDNS) traffic associated with a monitored cloud environment. The recursive DNS traffic includes recursive DNS (rDNS) requests originating from the cloud environment and responses to those requests received from DNS resolvers. This collected data is then analyzed to identify potential threats to the monitored cloud environment. The collected data may be analyzed to identify potential sources of threats and to identify one or more portions of the cloud environment that are the targets of the threats. The analysis may trigger alerts to be generated, actions to be performed (e.g., protective measures), reports to be generated, patterns to be recognized, etc.
    Type: Grant
    Filed: September 13, 2023
    Date of Patent: May 5, 2026
    Assignee: Oracle International Corporation
    Inventors: Christopher Robert Baker, Peter Martin Hanily, Ryan Daniel Schilcher, Jonathan Philip Taimanglo
  • Publication number: 20260087143
    Abstract: Techniques for detecting inter-tenancy exfiltration of data in a cloud environment are disclosed. A log that includes information associated with receipt of a service message at a gateway within a cloud environment is accessed. Based on the log, (i) originating information of the service message (such as identification of an originating tenancy of the service message) and (ii) target information of the service message (such as identification of a target tenancy of the service message) are determined. The originating information and the target information are compared. A mismatch between the originating information of the service message and the target information of the service message is detected. In response to the detected mismatch between the originating information of the service message and the target information of the service message, information indicative of the detected mismatch is caused to be presented at a user interface.
    Type: Application
    Filed: September 24, 2024
    Publication date: March 26, 2026
    Applicant: Oracle International Corporation
    Inventors: Peter Martin Hanily, Ryan Daniel Schilcher, Christopher Robert Baker, Jonathan Philip Taimanglo
  • Publication number: 20260089179
    Abstract: Techniques for detecting stealing of principals in a cloud environment are disclosed. A request for a non-user principal to be used within a cloud environment is received. A log, which includes information associated with a receipt of the request for the non-user principal, is accessed. Based at least in part on the log, originating information of the request is determined. An anomaly associated with the originating information of the request is detected. In response to detecting the anomaly associated with the originating information of the request, information indicative of the detected anomaly associated with the originating information of the request is caused to be presented. In an example, the non-user principal is one of an instance principal, a resource principal, or a service principal to be assigned to a compute instance, a cloud resource, or a service, respectively, of the cloud environment.
    Type: Application
    Filed: September 24, 2024
    Publication date: March 26, 2026
    Applicant: Oracle International Corporation
    Inventors: Peter Martin Hanily, Ryan Daniel Schilcher, Christopher Robert Baker, Jonathan Philip Taimanglo
  • Publication number: 20260039454
    Abstract: Techniques for detected reuse of a public key of a public/private cryptographic key pair within a cloud environment are disclosed. A database maintained within a cloud environment is accessed, the database storing a plurality of public keys. Each public key has a corresponding attribute, and the database further stores a plurality of attributes corresponding to the plurality of public keys. Each public key is associated with either (i) a corresponding user account of a corresponding tenancy of the cloud environment or (ii) a compute instance hosted within a corresponding tenancy of the cloud environment. A number of times a first public key or a first attribute corresponding to the first public key occurring within the database is determined. Responsive to the number of times being equal to or greater than a threshold number, the first public key is tagged as being reused for at least the threshold number of times.
    Type: Application
    Filed: July 30, 2024
    Publication date: February 5, 2026
    Applicant: Oracle International Corporation
    Inventors: Peter Martin Hanily, Ryan Daniel Schilcher, Christopher Robert Baker, Jonathan Philip Taimanglo
  • Publication number: 20260032135
    Abstract: Cyber-security techniques are described for monitoring a cloud environment and can be used to identify potential problems, including malicious threats, to the monitored cloud environment using operational telemetry. Techniques are described for monitoring and collecting data related to reverse or recursive DNS (rDNS) traffic associated with a monitored cloud environment. The recursive DNS traffic includes recursive DNS (rDNS) requests originating from the cloud environment and responses to those requests received from DNS resolvers. This collected data is then analyzed to identify potential threats to the monitored cloud environment. The collected data may be analyzed to identify potential sources of threats and to identify one or more portions of the cloud environment that are the targets of the threats. The analysis may trigger alerts to be generated, actions to be performed (e.g., protective measures), reports to be generated, patterns to be recognized, etc.
    Type: Application
    Filed: October 2, 2025
    Publication date: January 29, 2026
    Applicant: Oracle International Corporation
    Inventors: Christopher Robert BAKER, Peter Martin HANILY, Ryan Daniel SCHILCHER, Jonathan Philip TAIMANGLO
  • Publication number: 20250384061
    Abstract: A method for detecting an unaccounted tenancy within a cloud environment is disclosed. The method includes storing, within a first database, (i) identifiers of a set of active cloud resources, and (ii) for each active cloud resource, an identifier of a corresponding tenancy; and storing, within a second database, (i) identifiers of a set of tenancies, and (ii) for each tenancy within the set of tenancies, a corresponding tenancy status. Within the second database, each of a first subset of the set of tenancies has an active status, and each of a second subset of the set of tenancies has a terminated status. The method includes querying the first and second databases to identify a first active cloud resource within a first tenancy, such that the first tenancy has a terminated tenancy status; tagging the first tenancy with an unaccounted tag; and undertaking mitigating actions for the unaccounted first tenancy.
    Type: Application
    Filed: June 17, 2024
    Publication date: December 18, 2025
    Applicant: Oracle International Corporation
    Inventors: Peter Martin Hanily, Ryan Daniel Schilcher, Christopher Robert Baker, Jonathan Philip Taimanglo
  • Publication number: 20250355791
    Abstract: Cloud computing architecture is described for implementing test modules in a communication-controlled cloud environment with access to private data. The test modules perform synchronous tests on the private data and export test results to an analytic environment subject to data export policies. An analytic application is used to asynchronously analyze the test results in the analytic environment. The cloud computing architecture alternatively or additionally includes an interface for deploying investigation-bound cloud environments in restricted subnets. A collection of software is instantiated in the investigation-bound cloud environment, and the investigation-bound cloud environment may be accessed with remote access credentials using a remote access protocol for testing the collection of software. Information about the investigation-bound cloud environment displayed in the analytic application, and the analytic application and the restricted subnet are forcibly deleted when the investigation is complete.
    Type: Application
    Filed: May 15, 2024
    Publication date: November 20, 2025
    Applicant: Oracle International Corporation
    Inventors: Ryan Daniel Schilcher, Peter Martin Hanily, Joel Russell, Nicholas Benedetti
  • Publication number: 20250355783
    Abstract: Cloud computing architecture is described for implementing test modules in a communication-controlled cloud environment with access to private data. The test modules perform synchronous tests on the private data and export test results to an analytic environment subject to data export policies. An analytic application is used to asynchronously analyze the test results in the analytic environment. The cloud computing architecture alternatively or additionally includes an interface for deploying investigation-bound cloud environments in restricted subnets. A collection of software is instantiated in the investigation-bound cloud environment, and the investigation-bound cloud environment may be accessed with remote access credentials using a remote access protocol for testing the collection of software. Information about the investigation-bound cloud environment displayed in the analytic application, and the analytic application and the restricted subnet are forcibly deleted when the investigation is complete.
    Type: Application
    Filed: May 15, 2024
    Publication date: November 20, 2025
    Applicant: Oracle International Corporaion
    Inventors: Ryan Daniel Schilcher, Nicholas Benedetti, Joel Russell, Peter Martin Hanily
  • Publication number: 20230420147
    Abstract: Cyber-security techniques are described for monitoring a cloud environment and identifying potential problems, including malicious threats, to the monitored cloud environment using operational telemetry. Techniques are described for monitoring and collecting data related to reverse or recursive DNS (rDNS) traffic associated with a monitored cloud environment. The recursive DNS traffic includes recursive DNS (rDNS) requests originating from the cloud environment and responses to those requests received from DNS resolvers. This collected data is then analyzed to identify potential threats to the monitored cloud environment. The collected data may be analyzed to identify potential sources of threats and to identify one or more portions of the cloud environment that are the targets of the threats. The analysis may trigger alerts to be generated, actions to be performed (e.g., protective measures), reports to be generated, patterns to be recognized, etc.
    Type: Application
    Filed: September 13, 2023
    Publication date: December 28, 2023
    Applicant: Oracle International Corporation
    Inventors: Christopher Robert BAKER, Peter Martin HANILY, Ryan Daniel SCHILCHER, Jonathan Philip TAIMANGLO