DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This office Action is in response to the appeal brief filed on 10/25/2023. Claims 1, 11, and 15 are independent claims. Claim 13 was previously cancelled. Claims 1-12 and 14-21 have been examined and are pending. This Office Action is made Non-Final.
In view of the appeal brief filed on 10/25/2023, PROSECUTION IS HEREBY REOPENED. A new ground of rejection is set forth below.
To avoid abandonment of the application, appellant must exercise one of the following two options:
(1) file a reply under 37 CFR 1.111 (if this Office action is non-final) or a reply under 37 CFR 1.113 (if this Office action is final); or,
(2) initiate a new appeal by filing a notice of appeal under 37 CFR 41.31 followed by an appeal brief under 37 CFR 41.37. The previously paid notice of appeal fee and appeal brief fee can be applied to the new appeal. If, however, the appeal fees set forth in 37 CFR 41.20 have been increased since they were previously paid, then appellant must pay the difference between the increased fees and the amount previously paid.
A Supervisory Patent Examiner (SPE) has approved of reopening prosecution by signing below:
/LUU T PHAM/ Supervisory Patent Examiner, Art Unit 2439
Specification Objection
The disclosure is objected to because of the following informalities: The disclosure does not include “brief summary of the invention” section. See MPEP § 608.01(a) for details. Appropriate correction is required.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-12 and 14-21 are rejected under 35 U. S. C. 101 as being directed to non-statutory subject matter as being directed to an abstract idea without being integrated into a practical application or significantly more.
Regarding claims 1, 11 and 15, the claim is directed to an abstract idea as reciting the limitations “determining from the report a first malware instance;” “determining, from the report, relationships among the plurality of entities;” “generating a causality tree;” “determining a root node of the causality tree;” “associating indications … with the node;” “determining that a first node of the plurality of nodes corresponds to the reason for the verdict and designating the node as corresponding to the reason for the verdict.” Said steps are “mental process” as broadly interpreted said steps could be performed in the human mind and/or by a human using pencil/paper. Therefore, the claims recite an abstract idea.
Said abstract idea and/or judicial exception is not integrated into a practical application as the claim does not recite any other active steps that utilize determination result into a practical application. It’s noted that the claim 1 recites the limitation “displaying a visualization of the causality tree on a graphical user interface.” The displaying step is recited at high level of generality of displaying information which is a form of insignificant extra-solution activity (See MPEP 2106.05 for details). Claim 15 recites additional elements (i.e., processor). However, said additional elements are recited at a high-level of generality (i.e., as a generic processor performing a generic computer function of determining operations etc.,) such that it amounts no more than mere instructions to apply the exception or abstract idea using a generic computer component. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea.
The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the additional elements when considered both individually and as an ordered combination do not amount to significantly more than the abstract idea. As mentioned above, although the claims recite additional elements, said elements taken individually or as a combination, do not result in the claim amounting to significantly more than the abstract idea because as the additional elements perform generic computer content distributing functions routinely used in information technology field. See US Application 20200059481, US Application 20210263830. As discussed above, the additional elements recited at a high-level of generality such that they amount no more than mere instructions to apply the exception using a generic computer component. Therefore, the claim is directed to non-statutory subject matter.
Regarding dependent claims 2-10, 12, 14 and 16-21; claims 2-10, 12-14 and 16-21 are rejected under 35 U.S.C. 101 as being directed to an abstract idea without being integrated into a practical application or significantly more for the same reason discussed above. It’s noted that claim 2 recites the limitations “adding a node to the causality tree;” “determining if a process tree is associated with the entity in the report;” “adding a plurality of nodes to the causality tree;” Claim 3 recites the limitations “creating the root node of the causality tree” and “adding a node to the causality tree;” Claim 4 recites the limitations “adding a first node … to the causality tree” and “adding child nodes …;” Claim 6 recites the limitations “determining a plurality of objects” and “associating indications;” Claim 8 recites the limitations “determining counts” and “associating the counts with the node;” Claim 9 recites the limitations “displaying an indicator…;” Claim 12 recites the limitations “determine a count of indications;” Claim 14 recites the limitations “determine the first malware instance” and “determine a plurality of processes;” Claim 16 recites the limitations “determine that the primary malware instance is identified …;” Claim 17 recites the limitations “associate indications …;” Claim 18 recites the limitations “determine if one or more actions were initiated in the process” and “associate indications [] with the node;” Claim 19 recites the limitations “display a depiction;” Claim 20 recites the limitations “associate indications” and “associate with the node …” and Claim 21 recites the limitations “display and indicator …;” However, said limitations/steps are also mental processes and/or in a form of form of insignificant extra-solution activity as discussed above. As result claims 2-10, 12, 14 and 16-21 are also rejected under 35 U.S.C. 101 as being directed to an abstract idea without being integrated into a practical application or significantly more.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-6, 8, 10-12, and 14-20 are rejected under 35 U.S.C. 103 as being unpatentable over AMBICHL et al. (“AMBICHL,” US 20200042426, published on 02/06/2020) in view of Huang et al. (“Huang,” US 20150261955, published on 09/17/2015).
Regarding Claim 1;
AMBICHL discloses a method comprising:
parsing a report generated based on a security analysis of a detected software sample, the report comprising identifiers of a plurality of entities associated with a sequence of events that occurred during the security analysis and a verdict that the detected software sample is malicious (par 0053; fig. 1b; Identified transaction execution related anomalies are located on a topology element, and the connection data of the topology model used to identify topology entities; par 0069; creates a trigger event which is forwarded to a causality estimator for a detailed and focused causality analysis; par 0070; the analysis performed by causality estimator uses the topology model and the topology coordinates of available monitoring data to identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions);
determining from the report a first malware instance that corresponds to one of the plurality of entities and a plurality of actions and a plurality of behaviors recorded during the security analysis (par 0069; fig. 2b; creates a trigger event which is forwarded to a causality estimator for a detailed and focused causality analysis; par 0070; identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0098; the topology stack driven causal dependency searches for anomalies on the processing infrastructure used by an identified service instance; par 0102; identification of causal relationships between services showing abnormal response time behavior [] a causality search for response time related abnormal behavior would follow the call direction of the service instance dependency graph; par 0116; an abnormal operating condition was detected on an instance of service S. The topology stack related causality analysis may first search for anomalies that occurred on process A that provides service);
determining, from the report, relationships among the plurality of entities (par 0069; fig. 2b; creates a trigger event which is forwarded to a causality estimator for a detailed and focused causality analysis. Trigger events contain data specifying the type and the extend of an abnormal operation condition, the location of the abnormal operation condition and data describing the temporal extend of the abnormal operation condition; par 0070; identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0165; parent topology identification data identifying the parent or enclosing topology node for a given topology node, entity type data [] for topology parent relationships described by parent topology data are processes executed by a host computer system, where the host computing system is the parent entity);
generating a causality tree comprising a plurality of nodes and a plurality of edges that connects the plurality of nodes based on the relationships among the plurality of entities (par 0040; data records that used to create and store causality graphs that describe the causal relations between different identified unexpected operating conditions; par 0165; parent topology identification data identifying the parent or enclosing topology node for a given topology node, entity type data [] for topology parent relationships described by parent topology data are processes executed by a host computer system, where the host computing system is the parent entity par0187; causality event records and causality edge records used to represent identified causal relationships between identified abnormal operating conditions in form of a causality graph),
wherein each of the plurality of nodes corresponds to a respective one of the plurality of entities (par 0149; fig. 2c; analyze incoming and outgoing service data to identify those services instances and their call dependencies. Create corresponding topology nodes describing the services instances and topology communication nodes describing the call dependencies. Use the topology identification data identifying the processes on which portions of transactions where used to link created topology nodes describing service instances with the topology nodes describing the processes that provide those service instances. The parent topology identification data of a topology node describing a service instance may be set to the topology identification data of the topology node describing the process that provides the service instance), and
wherein generating the causality tree comprises determining a root node of the causality tree based on a first of the relationships corresponding to the first malware instance (par 0024; fig. 2b; root cause calculation afterward be performed on merged causality graphs to identify those events that are the most probably root cause of other events of the graph; par 0070; the analysis performed by causality estimator uses the topology model and the topology coordinates of available monitoring data to identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0077; the identified or updated global causality graphs are forwarded to a root cause calculator, which identifies those events that have the highest probability of being the root cause of the other events contained in the global causality graph; par 0116; an abnormal operating condition was detected on an instance of service S. The topology stack related causality analysis may first search for anomalies that occurred on process A that provides service [] the causality analysis may continue to examine host operating system B which executes process A [] host operating system B reveals no abnormal operating condition on host operating system B, therefore also the hypothesis that conditions on operating system B are causally related to the abnormal operating conditions on service rejected);
for each node of one or more of the plurality of nodes, associating indications of corresponding ones of the plurality of actions and indications of the plurality of behaviors with the node (par 0069; causality estimator for a detailed and focused causality analysis. Trigger events contain data specifying the type and the extend of an abnormal operation condition, the location of the abnormal operation condition and data describing the temporal extend of the abnormal operation condition; par 0070; identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0102; identification of causal relationships between services showing abnormal response time behavior [] a causality search for response time related abnormal behavior would follow the call direction of the service instance dependency graph and first check service instance for a response time related abnormal behavior that could be have caused the anomaly identified);
based on identifying in the report an indication of a reason for the verdict that the detected software sample is malicious, determining that a first node of the plurality of nodes corresponds to the reason for the verdict and designating the node as corresponding to the reason for the verdict (par 0069; causality estimator for a detailed and focused causality analysis. Trigger events contain data specifying the type and the extend of an abnormal operation condition, the location of the abnormal operation condition and data describing the temporal extend of the abnormal operation condition; par 0070; the analysis performed by causality estimator uses the topology model and the topology coordinates of available monitoring data to identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions); and
displaying a visualization of the causality tree on a graphical user interface (GUI) (par 0078; after root cause events were identified by the root cause calculator, the global event graphs forwarded for further processing, like sending notifications to users of the monitoring system, problem and causal dependency visualization).
AMBICHL discloses verdict that the detected software sample is abnormal as recited above, but do not explicitly disclose verdict that the detected software sample is malicious.
However, in an analogous art, Huang discloses malware detection system/method that includes:
verdict that the detected software sample is malicious (Huang: par 0062; forensics analyzers may be run against each evidence instance's raw data in some embodiments. These forensics analyzers generate multiple forensics reports for each instance of evidence, each forensics report may include four elements proofs, exhibits, interpretations, and correlations; par 0063; proofs may be a predefined set of facts. The forensic analyzer is designed to prove the existence of the predefined set of facts within a scene. Examples of proofs include the following: "suspicious-or-malicious-scripts Proofs may be a predefined set of facts. In various embodiments, the forensic analyzer is designed to prove the existence of the predefined set of facts within a scene. Examples of proofs may include the following: suspicious-or-malicious-scripts).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Huang with the method/system of AMBICHL to include verdict that the detected software sample is malicious. One would have been motivated to include forensic collectors. Each of the collectors may be configured to apply a domain specific language to a target; observe a set of temporal sequences and events of the target; determine presence of markers within the set of temporal sequences and events indicative of malware (Huang: abstract).
Regarding Claim 2;
The combination of AMBICHL and Huang disclose the method of claim 1,
AMBICHL discloses wherein pairs of the plurality of entities are related by one or more of the relationships (AMBICHL: par 0069; fig. 2b; creates a trigger event which is forwarded to a causality estimator for a detailed and focused causality analysis. Trigger events contain data specifying the type and the extend of an abnormal operation condition; par 0070; identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0165; parent topology identification data identifying the parent or enclosing topology node for a given topology node, entity type data [] for topology parent relationships described by parent topology data are processes executed by a host computer system, where the host computing system is the parent entity), and wherein generating the causality tree for each entity in the pairs of the plurality of entities (AMBICHL: par 0040; data records that used to create and store causality graphs that describe the causal relations between different identified unexpected operating conditions; par 0165; parent topology identification data identifying the parent or enclosing topology node for a given topology node, entity type data [] for topology parent relationships described by parent topology data are processes executed by a host computer system, where the host computing system is the parent entity; par0187; causality event records and causality edge records used to represent identified causal relationships between identified abnormal operating conditions in form of a causality graph), adding a node to the causality tree which corresponds to the entity (AMBICHL: par 0081; add additional clustered causality estimator nodes and reconfigure the trigger event data filters in a way that also the additional clustered causality estimator nodes process their share of trigger input data); determining if a process tree is associated with the entity in the report (AMBICHL: par 0069; creates a trigger event which is forwarded to a causality estimator for a detailed and focused causality analysis. Trigger events contain data specifying the type and the extend of an abnormal operation condition, the location of the abnormal operation condition and data describing the temporal extend of the abnormal operation condition; par 0070; identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0165; parent topology identification data identifying the parent or enclosing topology node for a given topology node, entity type data [] for topology parent relationships described by parent topology data are processes executed by a host computer system, where the host computing system is the parent entity); and based on determining that a process tree is associated with the entity, adding a plurality of nodes to the causality tree as children of the node which corresponds to the entity based, at least in part, on a hierarchical structure of processes in the process tree (AMBICHL: par 0069; creates a trigger event which is forwarded to a causality estimator for a detailed and focused causality analysis. Trigger events contain data specifying the type and the extend of an abnormal operation condition, the location of the abnormal operation condition and data describing the temporal extend of the abnormal operation condition; par 0070; identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0081; add additional clustered causality estimator nodes and reconfigure the trigger event data filters in a way that also the additional clustered causality estimator nodes process their share of trigger input data; par 0165; parent topology identification data identifying the parent or enclosing topology node for a given topology node, entity type data [] for topology parent relationships described by parent topology data are processes executed by a host computer system, where the host computing system is the parent entity; par 0193; Topologically reachable means in this an entity is either in a parent/child relationship, shares a parent entity or is involved in observed communication activity with the entity on which the input event occurred).
Regarding Claim 3;
The combination of AMBICHL and Huang disclose the method of claim 2,
AMBICHL discloses wherein each of the one or more relationships indicates a source entity and a target entity relationship (AMBICHL: par 0169; topology identification data identifying the topology entity on which the logging activity was monitored, a log identifier specifying the source of the log activity data within the topology entity; par 0165; parent topology identification data identifying the parent or enclosing topology node for a given topology node, entity type data [] for topology parent relationships described by parent topology data are processes executed by a host computer system, where the host computing system is the parent entity; par 0193; Topologically reachable means in this an entity is either in a parent/child relationship, shares a parent entity or is involved in observed communication activity with the entity on which the input event occurred), and wherein adding the node to the causality tree which corresponds to the entity comprises, based on determining that the entity is identified as a source entity in a first of the one or more relationships and is not identified as a target entity in any of the one or more relationships, creating the root node of the causality tree (AMBICHL: par 0024; root cause calculation afterward be performed on merged causality graphs to identify those events that are the most probably root cause of other events of the graph; par 0077; the identified or updated global causality graphs are forwarded to a root cause calculator, which identifies those events that have the highest probability of being the root cause of the other events contained in the global causality graph; par 0082; graphically describes the identification of causal dependencies on a transaction/service execution level [] identifying the processes involved in the transaction execution and data describing the communication interfaces of those processes that were used to transfer requests and responses between the processes involved in the transaction execution. The service topology and measurement extractor analyzes end-to-end transaction records to extract the communication interfaces used by those transactions and service topology entities [] connected to corresponding process entities in the topology model that provide those services; par 0081; add additional clustered causality estimator nodes and reconfigure the trigger event data filters in a way that also the additional clustered causality estimator nodes process their share of trigger input data), wherein the root node corresponds to the first malware instance or corresponds to another of the plurality of entities that indicates the first malware instance as a target entity (AMBICHL: par 0024; root cause calculation afterward be performed on merged causality graphs to identify those events that are the most probably root cause of other events of the graph; par 0070; the analysis performed by causality estimator uses the topology model and the topology coordinates of available monitoring data to identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0077; the identified or updated global causality graphs are forwarded to a root cause calculator, which identifies those events that have the highest probability of being the root cause of the other events contained in the global causality graph; par 0078; after root cause events were identified by the root cause calculator, the global event graphs forwarded for further processing, like sending notifications to users of the monitoring system, problem and causal dependency visualization or persistent storage; par 0116; an abnormal operating condition was detected on an instance of service S. The topology stack related causality analysis may first search for anomalies that occurred on process A that provides service); and based on determining that the entity is identified as a target entity in a first of the one or more relationships, adding a node to the causality tree as a child of a node which corresponds to its respective source entity (AMBICHL: par 0069; a causality estimator for a detailed and focused causality analysis; par 0070; identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0165; parent topology identification data identifying the parent or enclosing topology node for a given topology node, entity type data [] for topology parent relationships described by parent topology data are processes executed by a host computer system, where the host computing system is the parent entity; par 0081; add additional clustered causality estimator nodes and reconfigure the trigger event data filters in a way that also the additional clustered causality estimator nodes process their share of trigger input data; par 0165; parent topology identification data identifying the parent or enclosing topology node for a given topology node, entity type data [] for topology parent relationships described by parent topology data are processes executed by a host computer system, where the host computing system is the parent entity).
Regarding Claim 4;
The combination of AMBICHL and Huang disclose the method of claim 2,
AMBICHL discloses wherein adding the plurality of nodes to the causality tree comprises, based on determining a parent process of the process tree, adding a first node which corresponds to the parent process to the causality tree as a child of the node which corresponds to the entity (AMBICHL: par 0193; processing of a causality rule by the causality estimator. The process starts with when a causality rule and an input event was received, e.g. by the execution of the process “Calculate Causal Dependencies of Event” [] in this context that an entity is either in a parent/child relationship (e.g. a process running on a host computing system); par 0197; the currently processed hypothesis did not generate a new event for the causality graph but only added a new causal connection between already existing events; par 0214; causal event graph with a new event describing a new identified abnormal operating condition that has a causal relationship with one or more events already existing in the graph. then continues the search for other abnormal operating conditions that are causal related to the new added event); and for each child process remaining in the process tree, adding a node which corresponds to the child process to the causality tree as a child of the first node (AMBICHL: par 0193; processing of a causality rule by the causality estimator. The process starts with when a causality rule and an input event was received, e.g. by the execution of the process “Calculate Causal Dependencies of Event” [] in this context that an entity is either in a parent/child relationship (e.g. a process running on a host computing system); par 0197; the currently processed hypothesis did not generate a new event for the causality graph but only added a new causal connection between already existing events; par 0214; causal event graph with a new event describing a new identified abnormal operating condition that has a causal relationship with one or more events already existing in the graph. then continues the search for other abnormal operating conditions that are causal related to the new added event); and adding additional child nodes for children of the child process indicated in the process tree (AMBICHL: par 0193; processing of a causality rule by the causality estimator. The process starts with when a causality rule and an input event was received, e.g. by the execution of the process “Calculate Causal Dependencies of Event” [] in this context that an entity is either in a parent/child relationship (e.g. a process running on a host computing system); par 0197; the currently processed hypothesis did not generate a new event for the causality graph but only added a new causal connection between already existing events; par 0214; causal event graph with a new event describing a new identified abnormal operating condition that has a causal relationship with one or more events already existing in the graph. then continues the search for other abnormal operating conditions that are causal related to the new added event; par 0204; causal event graph with a new event describing a new identified abnormal operating condition that has a causal relationship with one or more events already existing in the graph. then continues the search for other abnormal operating conditions that are causal related to the new added event).
Regarding Claim 5;
The combination of AMBICHL and Huang disclose the method of claim 1,
Huang discloses wherein identifying in the report the indication of the reason for the verdict that the detected software sample is malicious is based, at least in part, on a field in the report with values corresponding to reasons for the verdict (Huang: par 0062; forensics analyzers may be run against each evidence instance's raw data in some embodiments. These forensics analyzers generate multiple forensics reports for each instance of evidence, each forensics report may include four elements proofs, exhibits, interpretations, and correlations; par 0063; proofs may be a predefined set of facts. The forensic analyzer is designed to prove the existence of the predefined set of facts within a scene. Examples of proofs include the following: "suspicious-or-malicious-scripts Proofs may be a predefined set of facts. In various embodiments, the forensic analyzer is designed to prove the existence of the predefined set of facts within a scene. Examples of proofs may include the following: suspicious-or-malicious-scripts), wherein displaying the visualization of the causality tree comprises visually distinguishing a graphical element that represents the first node as corresponding to a reason for the verdict (Huang: par 0062; forensics analyzers may be run against each evidence instance's raw data in some embodiments. These forensics analyzers generate multiple forensics reports for each instance of evidence, each forensics report may include four elements proofs, exhibits, interpretations, and correlations; par 0063; proofs may be a predefined set of facts. The forensic analyzer is designed to prove the existence of the predefined set of facts within a scene. Examples of proofs include the following: "suspicious-or-malicious-scripts Proofs may be a predefined set of facts. In various embodiments, the forensic analyzer is designed to prove the existence of the predefined set of facts within a scene. Examples of proofs may include the following: suspicious-or-malicious-scripts; par 0067; correlations used within a forensics report to express causal relationships between evidences. Each evidence can have a single causal evidence, but may have multiple resulting evidences. Therefore, the causal relationships of an entire scene can be visualized using a tree representation).
One would have been motivated to include forensic collectors. Each of the collectors may be configured to apply a domain specific language to a target; observe a set of temporal sequences and events of the target; determine presence of markers within the set of temporal sequences and events indicative of malware (Huang: abstract).
Regarding Claim 6;
The combination of AMBICHL and Huang disclose the method of claim 1,
AMBICHL discloses determining a plurality of objects associated with the plurality of actions based, at least in part, on fields in the report which indicate inputs to and outputs of each of the plurality of actions, wherein each of the plurality of objects is an input to or an output of a corresponding one of the plurality of actions (AMBICHL: par 0135; fig. 4; processes that may be used on a monitoring server to process various types of monitoring data received from agents or APIs deployed to a monitored environment; par 0136; the processing of topology records performed by a topology data processor. When the topology data processor receives topology record. fetches the topology entity that corresponds to the received topology record from the topology model. Use the topology identification data contained in the received topology record to identify and fetch a topology node contained in the topology model with matching topology identification data; par 0137; determines if a topology model entity corresponding to the received topology record already exists in the topology model. Executed which creates a new topology model entity using the data of the received topology record. This also contains the linking of the newly created topology entity with its corresponding parent entity); and for each node of the one or more of the plurality of nodes, associating indications of corresponding ones of the plurality of objects with the node (AMBICHL: par 0069; fig. 2b; creates a trigger event which is forwarded to a causality estimator for a detailed and focused causality analysis. Trigger events contain data specifying the type and the extend of an abnormal operation condition; par 0070; identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0098; the topology stack driven causal dependency searches for anomalies on the processing infrastructure used by an identified service instance; par 0102; identification of causal relationships between services showing abnormal response time behavior [] a causality search for response time related abnormal behavior would follow the call direction of the service instance dependency graph and first check service instance for a response time related abnormal behavior that could be have caused the anomaly identified; par 0103; when a response time change event is received, which indicates a specific service instance on which the response time change occurred, together with a filtered service instance call [] analyzed to determine whether a response time change occurred in those service instances);
Regarding Claim 8;
The combination of AMBICHL and Huang disclose the method of claim 1,
AMBICHL discloses for each node of the one or more of the plurality of nodes, determining counts of each of the corresponding ones of the plurality of behaviors and plurality of actions and associating the counts with the node (AMBICHL: par 0069; causality estimator for a detailed and focused causality analysis. Trigger events contain data specifying the type and the extend of an abnormal operation condition, the location of the abnormal operation condition and data describing the temporal extend of the abnormal operation condition; par 0070; identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0102; identification of causal relationships between services showing abnormal response time behavior [] a causality search for response time related abnormal behavior would follow the call direction of the service instance dependency graph and first check service instance for a response time related abnormal behavior that could be have caused the anomaly identified; par 0250; determine if the identified maximum difference exceeds a certain threshold and may, therefore, be considered as a significant change; par 0253; Afterwards, decision determines whether a sufficient amount of reference change points is available. In case additional reference change points are required, the process continues with minimum required number of reference change points for this decision), wherein displaying the visualization of the causality tree on the GUI comprises displaying the counts for each of the one or more nodes (AMBICHL: par 0078; after root cause events were identified by the root cause calculator, the global event graphs forwarded for further processing, like sending notifications to users of the monitoring system, problem and causal dependency visualization).
Regarding Claim 10;
The combination of AMBICHL and Huang disclose the method of claim 1,
Huang discloses wherein each of the plurality of entities comprises a process, a file, or a malware instance (Huang: par 0045; entities that are somewhat like known malware , such as for Javascripts and binary downloads, and so forth. There can be, for instance, a certain confidence level that something detected is a variant of another known example malware. For example, in an attempt to disguise some new variant of a threat programmed in Javascript, malware authors may change the names of variables and non-useful code, and generally try to obfuscate the code).
One would have been motivated to include forensic collectors. Each of the collectors may be configured to apply a domain specific language to a target; observe a set of temporal sequences and events of the target; determine presence of markers within the set of temporal sequences and events indicative of malware (Huang: abstract).
Regarding Claim 11;
AMBICHL discloses one or more non-transitory machine-readable media comprising program code to:
parse a report generated from performing threat analysis based on detection of a potential threat, the report indicating a plurality of entities and a verdict that the potential threat is malicious (par 0069; fig. 1b; creates a trigger event which is forwarded to a causality estimator for a detailed and focused causality analysis. Trigger events contain data specifying the type and the extend of an abnormal operation condition, the location of the abnormal operation condition and data describing the temporal extend of the abnormal operation condition; par 0070; the analysis performed by causality estimator uses the topology model and the topology coordinates of available monitoring data to identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions);
determine a plurality of actions, a plurality of behaviors, and a plurality of objects associated with the plurality of actions recorded from the threat analysis that are indicated in the parsed report (par 0069; fig. 2b; creates a trigger event which is forwarded to a causality estimator for a detailed and focused causality analysis. Trigger events contain data specifying the type and the extend of an abnormal operation condition; par 0070; identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0098; the topology stack driven causal dependency searches for anomalies on the processing infrastructure used by an identified service instance; par 0102; identification of causal relationships between services showing abnormal response time behavior [] a causality search for response time related abnormal behavior would follow the call direction of the service instance dependency graph and first check service instance for a response time related abnormal behavior that could be have caused the anomaly identified; par 0103; when a response time change event is received, which indicates a specific service instance on which the response time change occurred, together with a filtered service instance call [] analyzed to determine whether a response time change occurred in those service instances);
determine a root entity of a causality tree based on identification of a first malware instance indicated in the report, wherein the first malware instance corresponds to one of the plurality of entities (par 0024; root cause calculation afterward be performed on merged causality graphs to identify those events that are the most probably root cause of other events of the graph; par 0070; the analysis performed by causality estimator uses the topology model and the topology coordinates of available monitoring data to identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0077; the identified or updated global causality graphs are forwarded to a root cause calculator, which identifies those events that have the highest probability of being the root cause of the other events contained in the global causality graph; par 0078; after root cause events were identified by the root cause calculator, the global event graphs forwarded for further processing, like sending notifications to users of the monitoring system, problem and causal dependency visualization or persistent storage);;
initialize the causality tree with a root node corresponding to the root entity (par 0024; root cause calculation afterward be performed on merged causality graphs to identify those events that are the most probably root cause of other events of the graph; par 0070; the analysis performed by causality estimator uses the topology model and the topology coordinates of available monitoring data to identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0077; the identified or updated global causality graphs are forwarded to a root cause calculator, which identifies those events that have the highest probability of being the root cause of the other events contained in the global causality graph; par 0078; after root cause events were identified by the root cause calculator, the global event graphs forwarded for further processing, like sending notifications to users of the monitoring system, problem and causal dependency visualization or persistent storage);
determine a hierarchical structure of the plurality of entities indicated in the parsed report and add a plurality of nodes which identify corresponding ones of the plurality of entities to the causality tree (par 0069; creates a trigger event which is forwarded to a causality estimator for a detailed and focused causality analysis; par 0081; add additional clustered causality estimator nodes and reconfigure the trigger event data filters in a way that also the additional clustered causality estimator nodes process their share of trigger input data; par 0165; parent topology identification data identifying the parent or enclosing topology node for a given topology node, entity type data [] for topology parent relationships described by parent topology data are processes executed by a host computer system, where the host computing system is the parent entity),
wherein each of the plurality of nodes is added to the causality tree based on the hierarchical structure of the plurality of entities (par 0069; creates a trigger event which is forwarded to a causality estimator for a detailed and focused causality analysis; par 0081; add additional clustered causality estimator nodes and reconfigure the trigger event data filters in a way that also the additional clustered causality estimator nodes process their share of trigger input data; par 0165; parent topology identification data identifying the parent or enclosing topology node for a given topology node, entity type data [] for topology parent relationships described by parent topology data are processes executed by a host computer system, where the host computing system is the parent entity); and
for each node of one or more of the plurality of nodes, associate with the node indications of corresponding ones of the plurality of actions, plurality of behaviors, and plurality of observable objects (par 0069; causality estimator for a detailed and focused causality analysis. Trigger events contain data specifying the type and the extend of an abnormal operation condition, the location of the abnormal operation condition and data describing the temporal extend of the abnormal operation condition; par 0070; identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0102; identification of causal relationships between services showing abnormal response time behavior [] a causality search for response time related abnormal behavior would follow the call direction of the service instance dependency graph and first check service instance for a response time related abnormal behavior that could be have caused the anomaly identified).
AMBICHL discloses a verdict that the potential threat is abnormal as recited above, but do not explicitly disclose based on a determination that the node corresponds to a reason indicated in the report for the verdict that the potential threat is malicious, mark the node as corresponding to a reason for the verdict.
However, in an analogous art, Huang discloses malware detection system/method that includes:
based on a determination that the node corresponds to a reason indicated in the report for the verdict that the potential threat is malicious, mark the node as corresponding to a reason for the verdict (Huang: par 0062; forensics analyzers may be run against each evidence instance's raw data in some embodiments. These forensics analyzers generate multiple forensics reports for each instance of evidence, each forensics report may include four elements proofs, exhibits, interpretations, and correlations; par 0063; proofs may be a predefined set of facts. The forensic analyzer is designed to prove the existence of the predefined set of facts within a scene. Examples of proofs include the following: "suspicious-or-malicious-scripts Proofs may be a predefined set of facts. In various embodiments, the forensic analyzer is designed to prove the existence of the predefined set of facts within a scene. Examples of proofs may include the following: suspicious-or-malicious-scripts).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Huang with the method/system of AMBICHL to include based on a determination that the node corresponds to a reason indicated in the report for the verdict that the potential threat is malicious, mark the node as corresponding to a reason for the verdict. One would have been motivated to include forensic collectors. Each of the collectors may be configured to apply a domain specific language to a target; observe a set of temporal sequences and events of the target; determine presence of markers within the set of temporal sequences and events indicative of malware (Huang: abstract).
Regarding Claim 12;
The combination of AMBICHL and Huang disclose the non-transitory machine-readable media of claim 11,
AMBICHL discloses program code to, for each node of the plurality of nodes, determine a count of indications of the corresponding ones of the plurality of actions associated with the node and a count of indications of the corresponding ones of the plurality of behaviors of associated with the node and associate the determined counts with each node of the plurality of nodes (AMBICHL: par 0069; causality estimator for a detailed and focused causality analysis. Trigger events contain data specifying the type and the extend of an abnormal operation condition, the location of the abnormal operation condition and data describing the temporal extend of the abnormal operation condition; par 0070; identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0102; identification of causal relationships between services showing abnormal response time behavior [] a causality search for response time related abnormal behavior would follow the call direction of the service instance dependency graph and first check service instance for a response time related abnormal behavior that could be have caused the anomaly identified; par 0250; determine if the identified maximum difference exceeds a certain threshold and may, therefore, be considered as a significant change; par 0253; Afterwards, decision determines whether a sufficient amount of reference change points is available. In case additional reference change points are required, the process continues with minimum required number of reference change points for this decision).
Regarding Claim 14;
The combination of AMBICHL and Huang disclose the non-transitory machine-readable media of claim 11,
AMBICHL discloses wherein the program code to determine the hierarchical structure comprises program code to determine the first malware instance identified from the threat analysis and determine a plurality of processes associated with the first malware instance in the report (AMBICHL: par 0069; creates a trigger event which is forwarded to a causality estimator for a detailed and focused causality analysis; par 0165; parent topology identification data identifying the parent or enclosing topology node for a given topology node, entity type data [] for topology parent relationships described by parent topology data are processes executed by a host computer system, where the host computing system is the parent entity; par 0193; Topologically reachable means in this an entity is either in a parent/child relationship, shares a parent entity or is involved in observed communication activity with the entity on which the input event occurred; par 0116; an abnormal operating condition was detected on an instance of service S. The topology stack related causality analysis may first search for anomalies that occurred on process A that provides service [] the causality analysis may continue to examine host operating system B which executes process A [] host operating system B reveals no abnormal operating condition on host operating system B, therefore also the hypothesis that conditions on operating system B are causally related to the abnormal operating conditions on service rejected).
Regarding Claim 15;
AMBICHL discloses an apparatus comprising:
a processor; and a non-transitory computer-readable medium having instructions stored thereon that are executable by the processor to cause the apparatus to (par 0267; The computer programs include processor-executable instructions that are stored on a non-transitory tangible computer readable medium),
parse a report generated from a threat analysis of a software sample which indicates a verdict that the software sample is malicious and a primary malware instance detected from the threat analysis (par 0053; fig. 1b; Identified transaction execution related anomalies are located on a topology element, and the connection data of the topology model used to identify topology entities; par 0069; creates a trigger event which is forwarded to a causality estimator for a detailed and focused causality analysis; par 0070; the analysis performed by causality estimator uses the topology model and the topology coordinates of available monitoring data to identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0116; an abnormal operating condition was detected on an instance of service S. The topology stack related causality analysis may first search for anomalies that occurred on process A that provides service [] the causality analysis may continue to examine host operating system B which executes process A [] host operating system B reveals no abnormal operating condition on host operating system B, therefore also the hypothesis that conditions on operating system B are causally related to the abnormal operating conditions on service rejected);
create a root node of a causality tree based, at least in part, on a relationship indicated in the report which identifies the primary malware instance (par 0024; fig. 2b; root cause calculation afterward be performed on merged causality graphs to identify those events that are the most probably root cause of other events of the graph; par 0070; the analysis performed by causality estimator uses the topology model and the topology coordinates of available monitoring data to identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0077; the identified or updated global causality graphs are forwarded to a root cause calculator, which identifies those events that have the highest probability of being the root cause of the other events contained in the global causality graph; par 0116; an abnormal operating condition was detected on an instance of service S. The topology stack related causality analysis may first search for anomalies that occurred on process A that provides service [] the causality analysis may continue to examine host operating system B which executes process A [] host operating system B reveals no abnormal operating condition on host operating system B, therefore also the hypothesis that conditions on operating system B are causally related to the abnormal operating conditions on service rejected);
based on a determination that the report indicates a process tree that corresponds to the primary malware instance, for each process in the process tree, add a node which identifies the process to the causality tree as a child node (par 0024; root cause calculation afterward be performed on merged causality graphs to identify those events that are the most probably root cause of other events of the graph; par 0077; the identified or updated global causality graphs are forwarded to a root cause calculator, which identifies those events that have the highest probability of being the root cause of the other events contained in the global causality graph; par 0082; graphically describes the identification of causal dependencies on a transaction/service execution level [] identifying the processes involved in the transaction execution and data describing the communication interfaces of those processes that were used to transfer requests and responses between the processes involved in the transaction execution. The service topology and measurement extractor analyzes end-to-end transaction records to extract the communication interfaces used by those transactions and service topology entities [] connected to corresponding process entities in the topology model that provide those services; par 0116; an abnormal operating condition was detected on an instance of service S. The topology stack related causality analysis may first search for anomalies that occurred on process A that provides service [] the causality analysis may continue to examine host operating system B which executes process A [] host operating system B reveals no abnormal operating condition on host operating system B, therefore also the hypothesis that conditions on operating system B are causally related to the abnormal operating conditions on service rejected; par 0081; add additional clustered causality estimator nodes and reconfigure the trigger event data filters in a way that also the additional clustered causality estimator nodes process their share of trigger input data);
for each node in the causality tree, determine if at least one of one or more actions and one or more behaviors are associated with an entity corresponding to the node in the report (par 0069; causality estimator for a detailed and focused causality analysis. Trigger events contain data specifying the type and the extend of an abnormal operation condition, the location of the abnormal operation condition and data describing the temporal extend of the abnormal operation condition; par 0070; identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0102; identification of causal relationships between services showing abnormal response time behavior [] a causality search for response time related abnormal behavior would follow the call direction of the service instance dependency graph and first check service instance for a response time related abnormal behavior that could be have caused the anomaly identified); and
based on a determination that at least one of one or more actions and one or more behaviors are associated with the entity, associate indications of the at least one of the one or more actions and the one or more behaviors with the node (par 0069; causality estimator for a detailed and focused causality analysis. Trigger events contain data specifying the type and the extend of an abnormal operation condition, the location of the abnormal operation condition and data describing the temporal extend of the abnormal operation condition; par 0070; identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0102; identification of causal relationships between services showing abnormal response time behavior [] a causality search for response time related abnormal behavior would follow the call direction of the service instance dependency graph and first check service instance for a response time related abnormal behavior that could be have caused the anomaly identified);
designate the node as corresponding to a reason for the verdict (par 0069; causality estimator for a detailed and focused causality analysis. Trigger events contain data specifying the type and the extend of an abnormal operation condition, the location of the abnormal operation condition and data describing the temporal extend of the abnormal operation condition; par 0070; the analysis performed by causality estimator uses the topology model and the topology coordinates of available monitoring data to identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions).
AMBICHL discloses a verdict that the software sample is abnormal as recited above, but do not explicitly disclose based on a determination that the node corresponds to a reason indicated in the report for the verdict that the software sample is malicious.
However, in an analogous art, Huang discloses malware detection system/method that includes:
based on a determination that the node corresponds to a reason indicated in the report for the verdict that the software sample is malicious (Huang: par 0062; forensics analyzers may be run against each evidence instance's raw data in some embodiments. These forensics analyzers generate multiple forensics reports for each instance of evidence, each forensics report may include four elements proofs, exhibits, interpretations, and correlations; par 0063; proofs may be a predefined set of facts. The forensic analyzer is designed to prove the existence of the predefined set of facts within a scene. Examples of proofs include the following: "suspicious-or-malicious-scripts Proofs may be a predefined set of facts. In various embodiments, the forensic analyzer is designed to prove the existence of the predefined set of facts within a scene. Examples of proofs may include the following: suspicious-or-malicious-scripts).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Huang with the method/system of AMBICHL to include based on a determination that the node corresponds to a reason indicated in the report for the verdict that the software sample is malicious. One would have been motivated to include forensic collectors. Each of the collectors may be configured to apply a domain specific language to a target; observe a set of temporal sequences and events of the target; determine presence of markers within the set of temporal sequences and events indicative of malware (Huang: abstract).
Regarding Claim 16;
The combination of AMBICHL and Huang disclose the apparatus of claim 15,
AMBICHL discloses wherein the instructions executable by the processor to cause the apparatus to create the root node comprise instructions executable by the processor to cause the apparatus to determine that the primary malware instance is identified as corresponding to a source entity or a target entity in the relationship, wherein the root node that is created identifies the source entity (AMBICHL: par 0024; fig. 2b; root cause calculation afterward be performed on merged causality graphs to identify those events that are the most probably root cause of other events of the graph; par 0070; the analysis performed by causality estimator uses the topology model and the topology coordinates of available monitoring data to identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0077; the identified or updated global causality graphs are forwarded to a root cause calculator, which identifies those events that have the highest probability of being the root cause of the other events contained in the global causality graph; par 0116; an abnormal operating condition was detected on an instance of service S. The topology stack related causality analysis may first search for anomalies that occurred on process A that provides service [] the causality analysis may continue to examine host operating system B which executes process A [] host operating system B reveals no abnormal operating condition on host operating system B, therefore also the hypothesis that conditions on operating system B are causally related to the abnormal operating conditions on service rejected);
Regarding Claim 17;
The combination of AMBICHL and Huang disclose the apparatus of claim 15,
AMBICHL discloses instructions executable by the processor to, based on a determination that one or more actions are associated with the entity corresponding to the node, determine one or more computing objects indicated as inputs to or outputs of a corresponding action of the one or more actions in the report (AMBICHL: par 0135; fig. 4; processes that may be used on a monitoring server to process various types of monitoring data received from agents or APIs deployed to a monitored environment; par 0136; the processing of topology records performed by a topology data processor. When the topology data processor receives topology record. fetches the topology entity that corresponds to the received topology record from the topology model. Use the topology identification data contained in the received topology record to identify and fetch a topology node contained in the topology model with matching topology identification data; par 0137; determines if a topology model entity corresponding to the received topology record already exists in the topology model. Executed which creates a new topology model entity using the data of the received topology record. This also contains the linking of the newly created topology entity with its corresponding parent entity), wherein the instructions executable by the processor to cause the apparatus to associate indications of the one or more actions with the node comprise instructions executable by the processor to cause the apparatus to associate indications of the one or more computing objects with the corresponding action of the one or more actions (AMBICHL: par 0069; causality estimator for a detailed and focused causality analysis. Trigger events contain data specifying the type and the extend of an abnormal operation condition, the location of the abnormal operation condition and data describing the temporal extend of the abnormal operation condition; par 0070; identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0102; identification of causal relationships between services showing abnormal response time behavior [] a causality search for response time related abnormal behavior would follow the call direction of the service instance dependency graph and first check service instance for a response time related abnormal behavior that could be have caused the anomaly identified);
Regarding Claim 18;
The combination of AMBICHL and Huang disclose the apparatus of claim 15,
AMBICHL discloses wherein the instructions executable by the processor to cause the apparatus to determine if one or more actions are associated with an entity corresponding to the node in the report comprise instructions executable by the processor to, for each process in the process tree, determine if one or more actions were initiated in the process (AMBICHL: par 0069; causality estimator for a detailed and focused causality analysis. Trigger events contain data specifying the type and the extend of an abnormal operation condition, the location of the abnormal operation condition and data describing the temporal extend of the abnormal operation condition; par 0070; identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0102; identification of causal relationships between services showing abnormal response time behavior [] a causality search for response time related abnormal behavior would follow the call direction of the service instance dependency graph and first check service instance for a response time related abnormal behavior that could be have caused the anomaly identified), wherein the instructions executable by the processor to cause the apparatus to associate indications of the one or more actions with the node comprises instructions executable by the processor to cause the apparatus to, based on a determination that one or more actions were initiated in the process, associate indications of the one or more actions with the node corresponding to the process (AMBICHL: par 0069; causality estimator for a detailed and focused causality analysis. Trigger events contain data specifying the type and the extend of an abnormal operation condition, the location of the abnormal operation condition and data describing the temporal extend of the abnormal operation condition; par 0070; identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0102; identification of causal relationships between services showing abnormal response time behavior [] a causality search for response time related abnormal behavior would follow the call direction of the service instance dependency graph and first check service instance for a response time related abnormal behavior that could be have caused the anomaly identified; par 0104; checks if an abnormal response time behavior was detected on at least one called service. Executed which considers the identified service instances showing a response time anomaly for further causality estimation, e.g. by analyzing service instances called by those service instances in a subsequent execution or by performing a topology stack related causality search on those service instances).
Regarding Claim 19;
The combination of AMBICHL and Huang disclose the apparatus of claim 15,
AMBICHL discloses instructions executable by the processor to cause the apparatus to display a depiction of the causality tree on a graphical user interface (GUI), wherein the depiction of the causality tree comprises a plurality of GUI elements representing nodes of the causality tree and, for each GUI element of the plurality of GUI elements and corresponding node of the causality tree, at least one of a count of the indications of the one or more behaviors associated with the node and a count of the indications of the one or more actions associated with the node (AMBICHL: par 0069; causality estimator for a detailed and focused causality analysis. Trigger events contain data specifying the type and the extend of an abnormal operation condition, the location of the abnormal operation condition and data describing the temporal extend of the abnormal operation condition; par 0070; identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0078; after root cause events were identified by the root cause calculator, the global event graphs forwarded for further processing, like sending notifications to users of the monitoring system, problem and causal dependency visualization; par 0102; identification of causal relationships between services showing abnormal response time behavior [] a causality search for response time related abnormal behavior would follow the call direction of the service instance dependency graph and first check service instance for a response time related abnormal behavior that could be have caused the anomaly identified; par 0250; determine if the identified maximum difference exceeds a certain threshold and may, therefore, be considered as a significant change; par 0253; Afterwards, decision determines whether a sufficient amount of reference change points is available. In case additional reference change points are required, the process continues with minimum required number of reference change points for this decision).
Regarding Claim 20;
The combination of AMBICHL and Huang disclose the apparatus of claim 15,
AMBICHL discloses wherein the instructions executable by the processor to cause the apparatus associate indications of the at least one of the one or more actions and one or more behaviors with the node comprise instructions executable by the processor to cause the apparatus to associate with the node (AMBICHL: par 0069; causality estimator for a detailed and focused causality analysis. Trigger events contain data specifying the type and the extend of an abnormal operation condition, the location of the abnormal operation condition and data describing the temporal extend of the abnormal operation condition; par 0070; identify topological entities that are connected to topology entities corresponding to identified abnormal operating conditions; par 0102; identification of causal relationships between services showing abnormal response time behavior [] a causality search for response time related abnormal behavior would follow the call direction of the service instance dependency graph and first check service instance for a response time related abnormal behavior that could be have caused the anomaly identified), for each of the at least one of the one of the one or more actions and one or more behaviors, at least one of an identifier, name, description, and associated application programming interface (API) call indicated in the report (AMBICHL: par 0055; a monitoring server interacts with a heterogeneous set of agents and APIs deployed to a monitored environment. The agents may instrument elements of the monitored environments, like processes, host computing systems, network components or virtualization component and use this instrumentation to receive monitoring data describing structure, activities and resource usage of the monitored environment. APIs may provide interfaces for operators of the monitored environment to provide additional data about the monitored environment, like data describing changes in an underlying cloud computing system, or the update of hardware or software components of the monitored environment).
Claims 7, 9, and 21 are rejected under 35 U.S.C. 103 as being unpatentable over AMBICHL et al. (US 20200042426) in view of Huang et al. (US 20150261955), and further in view of Li et al. (“Li,” US 20210064751, published on 03/04/2021).
Regarding Claim 7;
The combination of AMBICHL and Huang disclose the method of claim 1,
AMBICHL discloses wherein each node of the plurality of nodes comprises fields for a name of an entity corresponding to the node, a type of the entity, a command executed via a command line, and a process identifier (AMBICHL: par 0116; fig. 2c; an abnormal operating condition was detected on an instance of service. The topology stack related causality analysis may first search for anomalies that occurred on process A that provides service; par 0118; Host computing system B is a virtualized host computing system provided by hypervisor C. Causality analysis may continue by examining hypervisor C for abnormal operating conditions that may explain the abnormal operating conditions identified on service).
The combination of AMBICHL and Huang disclose an entity as recited above, but do not explicitly disclose a type of the entity.
However, in an analogous art, Li discloses malware detection system/method that includes:
a type of the entity (Li: par 0042; the provenance-based threat detection tool can be configured to break provenance graphs into sample or causal paths, as features for detection, and uses the causal paths as the basic components for detection; par 0039; the provenance-based threat detection tool can monitor three types of entities: processes, files, and network communications).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Li with the method/system of The combination of AMBICHL and Huang to include a type of the entity. One would have been motivated to builds a provenance graph including a plurality of paths using a processor device from provenance data obtained from one or more computer systems and/or networks; detects anomalies in the embedded paths to identify malicious process activities, and terminates a process related to the embedded path having the identified malicious process activities (Li: abstract).
Regarding Claim 9;
The combination of AMBICHL and Huang disclose the method of claim 1 further comprising,
Huang discloses in response to selection of a graphical element that represents a first node of the causality tree, displaying an indicator of entity (Huang: par 67; correlations used within a forensics report to express causal relationships between evidences. Each evidence can have a single causal evidence, but may have multiple resulting evidences. Therefore, the causal relationships of an entire scene can be visualized using a tree representation).
One would have been motivated to include forensic collectors. Each of the collectors may be configured to apply a domain specific language to a target; observe a set of temporal sequences and events of the target; determine presence of markers within the set of temporal sequences and events indicative of malware (Huang: abstract).
The combination of WANG and Huang displaying an indicator of entity as recited above, but do not explicitly disclose a type of entity corresponding to the first node and descriptions of corresponding ones of the plurality of actions and the plurality of behaviors associated with the first node.
However, in an analogous art, Li discloses malware detection system/method that includes:
a type of entity corresponding to the first node and descriptions of corresponding ones of the plurality of actions and the plurality of behaviors associated with the first node (Li: par 0042; the provenance-based threat detection tool can be configured to break provenance graphs into sample or causal paths, as features for detection, and uses the causal paths as the basic components for detection; par 0039; the provenance-based threat detection tool can monitor three types of entities: processes, files, and network communications; par 0104; the provenance graph is built from the recorded provenance data, where hatched circles of the graph are nodes representing entities, and edges are events connecting the entities of the observed process. The provenance graph includes a plurality of actions by the process represented by the nodes and edges of the provenance graph. select portion of a provenance graph for a process that was initiated at node and proceeds through nodes. Multiple other processes can also be executing on a system (e.g., computer, network, server, etc.) [] the time stamp of each action can identify where in time the action took place, so the events on a causal graph are temporally ordered).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Li with the method/system of WANG and Huang to include a type of entity corresponding to the first node and descriptions of corresponding ones of the plurality of actions and the plurality of behaviors associated with the first node. One would have been motivated to builds a provenance graph including a plurality of paths using a processor device from provenance data obtained from one or more computer systems and/or networks; detects anomalies in the embedded paths to identify malicious process activities, and terminates a process related to the embedded path having the identified malicious process activities (Li: abstract).
Regarding Claim 21;
The combination of AMBICHL and Huang disclose the non-transitory machine-readable media of claim 12,
Huang discloses program code to, in response to selection of a graphical element that represents a first node of the causality tree, displaying an indicator (Huang: par 67; correlations used within a forensics report to express causal relationships between evidences. Each evidence can have a single causal evidence, but may have multiple resulting evidences. Therefore, the causal relationships of an entire scene can be visualized using a tree representation).
Huang discloses displaying an indicator of an entity as recited above, but do not explicitly disclose a type of entity corresponding to the first node and descriptions of the corresponding ones of the plurality of actions and the plurality of behaviors associated with the first node.
However, in an analogous art, Li discloses malware detection system/method that includes:
a type of entity corresponding to the first node and descriptions of the corresponding ones of the plurality of actions and the plurality of behaviors associated with the first node (Li: par 0042; the provenance-based threat detection tool can be configured to break provenance graphs into sample or causal paths, as features for detection, and uses the causal paths as the basic components for detection; par 0039; the provenance-based threat detection tool can monitor three types of entities: processes, files, and network communications; par 0104; the provenance graph is built from the recorded provenance data, where hatched circles of the graph are nodes representing entities, and edges are events connecting the entities of the observed process. The provenance graph includes a plurality of actions by the process represented by the nodes and edges of the provenance graph. select portion of a provenance graph for a process that was initiated at node and proceeds through nodes. Multiple other processes can also be executing on a system (e.g., computer, network, server, etc.) [] the time stamp of each action can identify where in time the action took place, so the events on a causal graph are temporally ordered).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Li with the method/system of AMBICHL and Huang to include a type of entity corresponding to the first node and descriptions of corresponding ones of the plurality of actions and the plurality of behaviors associated with the first node. One would have been motivated to builds a provenance graph including a plurality of paths using a processor device from provenance data obtained from one or more computer systems and/or networks; detects anomalies in the embedded paths to identify malicious process activities, and terminates a process related to the embedded path having the identified malicious process activities (Li: abstract).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHAO WANG whose telephone number is (313)446-6644. The examiner can normally be reached on Monday-Friday 7:30-4:30PM EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham can be reached on (571)270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see https://ppair-my.uspto.gov/pair/PrivatePair.
Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/C.W./Examiner, Art Unit 2439
/LUU T PHAM/Supervisory Patent Examiner, Art Unit 2439