Washington DC-Baltimore Area
2K followers 500+ connections

Join to view profile

About

With over 20 years leading the charge in cybersecurity, I am a recognized thought leader…

Articles by Matthew

Activity

2K followers

See all activities

Experience & Education

  • Primary

View Matthew’s full experience

See their title, tenure and more.

or

By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.

Licenses & Certifications

  • CISSP

    (ISC)²

    Issued
    Credential ID 306171
  • Security+

    CompTIA

    Issued
    Credential ID COMP001007645625
  • GIAC Penetration Tester (GPEN)

    GIAC Certifications

    Issued Expires
    Credential ID 12284
  • GIAC Certified Incident Handler (GCIH)

    GIAC Certifications

    Issued Expires
    Credential ID 21722
  • 6 Sigma Green Belt

    -

Publications

Patents

  • Single-packet authorization using proof of work

    Issued US11831638B1

    Methods, systems, and computer-readable media for single-packet authorization using proof of work are disclosed. An access control service receives, from a client, a single-packet authorization (SPA) request. The (SPA) request comprises output of a proof-of-work task, wherein completion of the proof-of-work task requires computational resources or memory resources of the client. The access control service performs verification of the output of the proof-of-work task using fewer computational or…

    Methods, systems, and computer-readable media for single-packet authorization using proof of work are disclosed. An access control service receives, from a client, a single-packet authorization (SPA) request. The (SPA) request comprises output of a proof-of-work task, wherein completion of the proof-of-work task requires computational resources or memory resources of the client. The access control service performs verification of the output of the proof-of-work task using fewer computational or memory resources of the access control service than were used by the client. In response to determining that verification of the output of the proof-of-work task succeeds, the access control service performs authentication of the SPA request. In response to determining that authentication of the SPA request succeeds, the access control service allows access by the client device to a service.

    See patent
  • Deperimeterized access control service

    Issued US011652822B2

    Techniques for deperimeterized access control are described. A method of deperimeterized access control may include receiving, by a controller of a deperimeterized access control service, a single packet authorization (SPA) request for a session ticket from an agent on a electronic device, wherein the agent sends the request for the session ticket in response to intercepting traffic destined for a service associated with the deperimeterized access control service and determining that the agent…

    Techniques for deperimeterized access control are described. A method of deperimeterized access control may include receiving, by a controller of a deperimeterized access control service, a single packet authorization (SPA) request for a session ticket from an agent on a electronic device, wherein the agent sends the request for the session ticket in response to intercepting traffic destined for a service associated with the deperimeterized access control service and determining that the agent does not have a session ticket for the service, authorizing the SPA request, providing a session ticket to the agent based on the request, receiving, by a gateway of the deperimeterized access control service, a request to initiate a session with a service, the request including the session ticket, validating the session ticket, and providing session parameters to the agent to be used to initiate the session between the electronic device and the service.

    See patent
  • Management and distribution of virtual cyber sensors

    Issued US 9,866,575

    A system includes reception of data at a computing network, generation of alerts at the computing network based on received data and on cyber sensor data, the cyber sensor data defining data attribute, reception of alerts from the computing network at a defense engine, detection of events based on the received alerts at the defense engine, generation threat data based on the detected events, generation of first cyber sensor data based on the threat data, and initiation of deployment of the…

    A system includes reception of data at a computing network, generation of alerts at the computing network based on received data and on cyber sensor data, the cyber sensor data defining data attribute, reception of alerts from the computing network at a defense engine, detection of events based on the received alerts at the defense engine, generation threat data based on the detected events, generation of first cyber sensor data based on the threat data, and initiation of deployment of the first cyber sensor data within the computing network.

    See patent
  • Honeyport active network security

    Issued US 9,436,652 and 9,838,426

    A device comprises a processor. The processor is configured to generate a first signal using a first communication protocol. The first signal corresponds to data received by the processor. The processor is configured to generate a second signal using a second communication protocol. The second signal comprises fabricated data generated by the processor. Additionally, the processor is configured to transmit the first signal. The processor is also configured to transmit the second…

    A device comprises a processor. The processor is configured to generate a first signal using a first communication protocol. The first signal corresponds to data received by the processor. The processor is configured to generate a second signal using a second communication protocol. The second signal comprises fabricated data generated by the processor. Additionally, the processor is configured to transmit the first signal. The processor is also configured to transmit the second signal.

    https://patentimages.storage.googleapis.com/35/eb/b9/0e6338bf783391/US9838426.pdf
    https://patentimages.storage.googleapis.com/f5/dd/35/56f30c7a511464/US9436652.pdf

    See patent
  • Load balancing medical imaging applications across healthcare imaging devices in reference to projected load based on user type

    Issued US 8,479,213

    Systems, methods and apparatus are provided through which in some embodiments healthcare imaging processing applications are allocated to computing resources in reference to criteria.

    See patent
  • Medical imaging system and method with integrated weight sensing

    Issued US 7,682,079

    An integrated weight sensing system and method is disclosed for a medical imaging system. In one embodiment, the integrated weight sensing system may include a table assembly, a load cell, and a processor that are implemented in a medical imaging system. The table assembly includes a lifting mechanism used to position a patient within the medical imaging system. The load cell is mechanically coupled to the table assembly and in communication with the processor. The load cell is configured to…

    An integrated weight sensing system and method is disclosed for a medical imaging system. In one embodiment, the integrated weight sensing system may include a table assembly, a load cell, and a processor that are implemented in a medical imaging system. The table assembly includes a lifting mechanism used to position a patient within the medical imaging system. The load cell is mechanically coupled to the table assembly and in communication with the processor. The load cell is configured to measure and indicate the weight of the patient and the processor may be configured to adjust imaging parameters based on the weight of the patient. The table assembly may include a device in communication with the load cell and/or processor to display the weight of the patient. Additionally, the table assembly and/or the processor may include an interface for zeroing or recalibrating the load cell.

    See patent
  • Real-Time Protection Framework for AI Agent Tool Systems

    Filed 19/468,695

    Systems, devices, and methods are provided for, among other things, dynamic, context-aware security for artificial intelligence (AI) systems that utilize external tools. Techniques may involve receiving a user input, determining metadata for available tools, and generating potential attack vectors based on the metadata. When the user input or set of user inputs presents as a potential risk for one or more of the known attack vectors, a security model can be selected based on the relevant attack…

    Systems, devices, and methods are provided for, among other things, dynamic, context-aware security for artificial intelligence (AI) systems that utilize external tools. Techniques may involve receiving a user input, determining metadata for available tools, and generating potential attack vectors based on the metadata. When the user input or set of user inputs presents as a potential risk for one or more of the known attack vectors, a security model can be selected based on the relevant attack vector(s) identified. The user input may be evaluated using the selected model to determine a proposed system component(s) to respond to the interaction, and multi-observer analysis may be applied to detect vulnerabilities. A weighted consensus from specialized observers may be used to determine a security intervention, such as restricting, modifying, or blocking execution.

  • Dynamic Multi-Level Token Management System for Large Language Models

    Filed 19/204,366 36

    Systems, devices, and methods are provided for multi-level tokenization in machine-learning models. Techniques described herein may relate to tokenization techniques that involve determining an input text and a label, selecting, based at least in part on the label, a first tokenizer from a plurality of tokenizers, using the first tokenizer to tokenize the input text and produce a first token sequence, analyzing the first token sequence to select a first trust level of a multi-trust level trust…

    Systems, devices, and methods are provided for multi-level tokenization in machine-learning models. Techniques described herein may relate to tokenization techniques that involve determining an input text and a label, selecting, based at least in part on the label, a first tokenizer from a plurality of tokenizers, using the first tokenizer to tokenize the input text and produce a first token sequence, analyzing the first token sequence to select a first trust level of a multi-trust level trust hierarchy, and determining a trusted token sequence by at least applying the first trust level to the first token sequence.

  • Embeddings Defense (EmDef)

    Filed 19/096,279 279

    Systems and methods are provided to detect anomalous data obtained from and/or to be routed to a machine learning model. A system can identify a first embedding generated by a machine learning model. The system can obtain a first set of data associated with the machine learning model and can compare the first embedding generated by the machine learning model with the first set of data. Based on comparing the first embedding generated by the machine learning model with the first set of data, the…

    Systems and methods are provided to detect anomalous data obtained from and/or to be routed to a machine learning model. A system can identify a first embedding generated by a machine learning model. The system can obtain a first set of data associated with the machine learning model and can compare the first embedding generated by the machine learning model with the first set of data. Based on comparing the first embedding generated by the machine learning model with the first set of data, the system can determine a manner of processing a second set of data (e.g., an input to and/or an output of the machine learning model). The system can process the second set of data according to the manner of processing the second set of data.

  • Generative AI and Honeypots

    Filed 19/095,879 879

    Techniques for using honeypots are described. In some examples, a method for using honeypots includes generating a honeypot having characteristics of a vulnerability as indicated in a publicly facing lure describing a vulnerable system, wherein the publicly facing lure includes one or more indications of a location of a honeypot and narratively refers to the honeypot as a vulnerable target; operating the generated honeypot to collect threat intelligence; generating one or more countermeasures…

    Techniques for using honeypots are described. In some examples, a method for using honeypots includes generating a honeypot having characteristics of a vulnerability as indicated in a publicly facing lure describing a vulnerable system, wherein the publicly facing lure includes one or more indications of a location of a honeypot and narratively refers to the honeypot as a vulnerable target; operating the generated honeypot to collect threat intelligence; generating one or more countermeasures based on the collected threat intelligence; and applying the one or more countermeasures.

  • MiRAGE: Dynamic Context Adaptation in Large Language Models Through Mid-Inference RAG

    Filed 19/096,274 274

    Systems and methods are provided to dynamically adjust contextual data of a machine learning model during an inference process of the machine learning model. A system can identify one or more tokens generated by the machine learning model. The machine learning model may, during an inference process, generate the one or more tokens based on first contextual data. The system can determine that the one or more tokens satisfy one or more first parameters. The system can obtain second contextual…

    Systems and methods are provided to dynamically adjust contextual data of a machine learning model during an inference process of the machine learning model. A system can identify one or more tokens generated by the machine learning model. The machine learning model may, during an inference process, generate the one or more tokens based on first contextual data. The system can determine that the one or more tokens satisfy one or more first parameters. The system can obtain second contextual data associated with the one or more tokens based on determining that the one or more tokens satisfy the one or more first parameters and can provide the second contextual data to the machine learning model. The machine learning model may generate an output based on the second contextual data and at least a portion of the first contextual data.

  • Privacy Preserving Mechanisms using Parameters and Tags

    Filed 19/096,153 153

    Systems and methods are provided to perform retrieval-augmented generation for machine learning models using filtered contextual data. A system can identify data associated with a machine learning model. The data may be associated with one or more first identifiers that may indicate a user, a user computing device, a model, etc. associated with the data. In response to determining that the data satisfies one or more parameters, the system can identify a need for contextual data. The system can…

    Systems and methods are provided to perform retrieval-augmented generation for machine learning models using filtered contextual data. A system can identify data associated with a machine learning model. The data may be associated with one or more first identifiers that may indicate a user, a user computing device, a model, etc. associated with the data. In response to determining that the data satisfies one or more parameters, the system can identify a need for contextual data. The system can compare the one or more first identifiers associated with the data to one or more second identifiers associated with the contextual data. Based on the comparison, the system can filter the contextual data to obtain filtered contextual data. The system may provide the filtered contextual data to the machine learning model for generation of an output.

Projects

Recommendations received

8 people have recommended Matthew

Join now to view

View Matthew’s full profile

  • See who you know in common
  • Get introduced
  • Contact Matthew directly
Join to view full profile

Other similar profiles

Explore top content on LinkedIn

Find curated posts and insights for relevant topics all in one place.

View top content

Add new skills with these courses