DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claims 1-9, 11-23, and 27-29 are pending in this application.
Response to Arguments
Applicant’s arguments regarding the rejections of claims 1-9 and 11-26 under 35 U.S.C. 112a/b have been fully considered and are persuasive. The rejections have been withdrawn. However, new 35 U.S.C. 112b rejections are applied to claim 21.
Applicant's arguments regarding the 35 U.S.C. 103 rejections of claims 1-9 and 11-26 have been fully considered but they are moot in light of the references being applied in the current rejection.
Claim Objections
Claims 1, 13, 14, and 23 are objected to because of the following informalities:
As per claims 1, 13, and 23 (line numbers refer to claim 1):
Lines 10-11 recite “increasing, by the computer an amount of one or more resources allocated to the one or more system-side applications are running within the HCI system” but “applications are running” should be replaced with “applications that are running”. Appropriate correction is required.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claim 21 is rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
As per claim 21:
Lines 5-6 recite “the other applications” but it is unclear what this refers to.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-9, 11-23, and 27-29 are rejected under 35 U.S.C. 103 as being unpatentable over Vohra et al. (US 20220253255 A1 hereinafter Vohra), in view of Siddappa et al. (US 20190034237 A1 hereinafter Siddappa), and further in view of Singh et al. (LEASH: Enhancing Micro-architectural Attack Detection with a Reactive Process Scheduler hereinafter Singh).
As per claim 1, Vohra teaches a computer-implemented method, comprising: identifying, by a computer, environmental information for a hyper-converged infrastructure (HCI) system ([0157] Readers will appreciate that the various components depicted in FIG. 3B may be grouped into one or more optimized computing packages as converged infrastructures. Such converged infrastructures may include pools of computers, storage and networking resources that can be shared by multiple applications and managed in a collective manner using policy-driven processes. Such converged infrastructures may minimize compatibility issues between various components within the storage system 306 while also reducing various costs associated with the establishment and operation of the storage system 306. Such converged infrastructures may be implemented with a converged infrastructure reference architecture, with standalone appliances, with a software driven hyper-converged approach (e.g., hyper-converged infrastructures), or in other ways; [0185] The storage systems described above may alone, or in combination with other computing resources, serves as a network edge platform that combines compute resources, storage resources, networking resources; [0208] The cloud-based storage system (403) may be used to provide services similar to the services that may be provided by the storage systems described above; [0116] Such data analytics applications may be configured, for example, to receive telemetry data phoned home by the storage system 306. Such telemetry data may describe various operating characteristics of the storage system 306 and may be analyzed, for example, to determine the health of the storage system 306 ); and
in response to determining that the environmental information indicates a need to perform data recovery operations within the HCI system due to failure of one or more hardware storage resources ([0288] In this example cloud storage architecture of the cloud-based storage system (1002), recovery from data loss may be implemented in multiple ways. As one example, within the non-durable cloud storage layer (1004), one or more of the cloud computing instances (424a-424n) may fail, or portions of storage (414, 426 . . . 422, 430) for one or more of the cloud computing instances (424a-424n) may fail; [0213] The cloud computing instances (424a, 424b, 424n) with local storage (414, 418, 422) may be embodied, for example, as EC2 M5 instances that include one or more SSDs, as EC2 R5 instances that include one or more SSDs, as EC2 13 instances that include one or more SSDs, and so on. In some embodiments, the local storage (414, 418, 422) must be embodied as solid-state storage (e.g., SSDs); [0292] loss of one or more cloud computing instances, such as the loss of cloud computing instance (424a); [0157] Readers will appreciate that the various components depicted in FIG. 3B may be grouped into one or more optimized computing packages as converged infrastructures. Such converged infrastructures may include pools of computers, storage and networking resources that can be shared by multiple applications and managed in a collective manner using policy-driven processes. Such converged infrastructures may minimize compatibility issues between various components within the storage system 306 while also reducing various costs associated with the establishment and operation of the storage system 306. Such converged infrastructures may be implemented with a converged infrastructure reference architecture, with standalone appliances, with a software driven hyper-converged approach (e.g., hyper-converged infrastructures), or in other ways; [0208] The cloud-based storage system (403) may be used to provide services similar to the services that may be provided by the storage systems described above; [0144] As such, one or more modules of computer program instructions that are executing within the cloud-based storage system 318 (e.g., a monitoring module that is executing on its own EC2 instance) may be designed to handle the failure of one or more of the cloud computing instances 340a, 340b, 340n with local storage 330, 334, 338. In such an example, the monitoring module may handle the failure of one or more of the cloud computing instances 340a, 340b, 340n with local storage 330, 334, 338 by creating one or more new cloud computing instances with local storage, retrieving data that was stored on the failed cloud computing instances 340a, 340b, 340n from the cloud-based object storage 348, and storing the data retrieved from the cloud-based object storage 348 in local storage on the newly created cloud computing instances):
identifying, by the computer, one or more system-side applications are running within the HCI system that are needed to perform the data recovery operations within the HCI system, increasing, by the computer, an amount of one or more resources allocated to the one or more system-side applications are running within the HCI system needed to perform the data recovery operations within the HCI system for reducing a time for performing the data recovery operations, and wherein the increased amount of the one or more resources allocated to the one or more system-side applications needed to perform the data recovery operations within the HCI system are retrieved, wherein the one or more system-side applications perform the data recovery operations using at least the increased amount of the one or more resources allocated to the one or more system-side applications ([0144] As such, one or more modules of computer program instructions that are executing within the cloud-based storage system 318 (e.g., a monitoring module that is executing on its own EC2 instance) may be designed to handle the failure of one or more of the cloud computing instances 340a, 340b, 340n with local storage 330, 334, 338. In such an example, the monitoring module may handle the failure of one or more of the cloud computing instances 340a, 340b, 340n with local storage 330, 334, 338 by creating one or more new cloud computing instances with local storage, retrieving data that was stored on the failed cloud computing instances 340a, 340b, 340n from the cloud-based object storage 348, and storing the data retrieved from the cloud-based object storage 348 in local storage on the newly created cloud computing instances; [0148] Readers will appreciate that various performance aspects of the cloud-based storage system 318 may be monitored (e.g., by a monitoring module that is executing in an EC2 instance) such that the cloud-based storage system 318 can be scaled-up or scaled-out as needed; [0157] Readers will appreciate that the various components depicted in FIG. 3B may be grouped into one or more optimized computing packages as converged infrastructures. Such converged infrastructures may include pools of computers, storage and networking resources that can be shared by multiple applications and managed in a collective manner using policy-driven processes. Such converged infrastructures may minimize compatibility issues between various components within the storage system 306 while also reducing various costs associated with the establishment and operation of the storage system 306. Such converged infrastructures may be implemented with a converged infrastructure reference architecture, with standalone appliances, with a software driven hyper-converged approach (e.g., hyper-converged infrastructures), or in other ways; [0208] The cloud-based storage system (403) may be used to provide services similar to the services that may be provided by the storage systems described above; [0279] In some implementations, the cloud-based storage system (1002) may be designed to recover from a data loss by scaling up the cloud architecture used to initially store the data to recover data more quickly than if the original cloud architecture were used.).
Vohra fails to teach wherein the increased amount of the one or more resources allocated to the one or more system-side applications are retrieved from resources allocated to a remaining one or more system-side applications within the HCI system other than the one or more system-side applications, in response to determining that the environmental information includes an existence of a security threat associated with a compromised user-side application, reducing an amount of merged resources currently allocated to the compromised user-side application.
However, Siddappa teaches wherein the increased amount of the one or more resources allocated to the one or more system-side applications are retrieved from resources allocated to a remaining one or more system-side applications within the HCI system other than the one or more system-side applications ([0024] In some examples, the workload selector 182 upon selecting a needy workload to receive additional resources (either based on the neediness of the workload or based on a request for resources from the needy workload) from an offering workload will identify an amount of additional resources that are needed. The workload selector 182 may identify the amount of additional resources that are needed based on information supplied by needy workload and/or based on a statistical analysis of the resources currently being consumed versus an amount of resources currently allotted to the needy workload. In some examples, the needy workload, upon consuming a threshold amount of allotted resources, may identify a need for additional resources to the workload selector 182. The threshold amount can be determined based on a static value or on a dynamic analysis of the resources being consumed across multiple workloads. The workload selector 182 then selects one of the offering workloads to lend resources to the needy workload. In some examples, the workload selector notifies the example resource configurer 178 that the amount of identified resources are to be lent from the selected offering workload to the needy workload; [0012] Enterprises that have migrated to a hyperconverged compute infrastructure often deploy workload domains to support enterprise applications. A workload domain (also referred to herein as a workload) provides compute, memory and storage resources to support execution of a set of enterprise applications having similar performance, availability, and security requirements. ).
It would have been obvious to one having ordinary skill in the art before the effective filling date of the claimed invention to have combined Vohra with the teachings of Siddappa to reduce the waste of resources (see Siddappa [0060] The resulting advantages include greater utilization of network resources and less waste of network resources.).
Vohra and Siddappa fail to teach in response to determining that the environmental information includes an existence of a security threat associated with a compromised user-side application, reducing an amount of merged resources currently allocated to the compromised user-side application.
However, Singh teaches in response to determining that the environmental information includes an existence of a security threat associated with a compromised user-side application, reducing an amount of merged resources currently allocated to the compromised user-side application (Section 2.2 paragraph 1 Most modern processors have a Performance Monitoring Unit on-chip to monitor micro-architectural events of running applications. Each logical core has a dedicated set of 4 to 8 configurable registers that can count the number of times a particular event occurs in a given duration. These registers are called Hardware Performance Counters (HPCs) and can be used to monitor a wide range of events like CPU-cycles, cache accesses, context-switches, and page faults; pg. 3 left column paragraph 2 LEASH, similarly uses HPCs to compute a threat index for a thread. Threads which depict a micro-architectural attack like behavior are given a high threat index and are throttled by reducing their CPU time; pg. 3 4. The LEASH Framework paragraph 1 Micro-architectural attacks depend considerably on CPU resources. If the attack programs are starved of the CPU, the success drops considerably; Fig. 1a caption LEASH stymies micro-architectural attacks by detecting malicious behavior in programs and reducing its CPU-share, thereby reducing the leakage from the shared resource; Section 1 paragraph 2 In a typical micro-architectural attack, the attacker runs a program called the spy that contends with a victim program for shared hardware resources).
It would have been obvious to one having ordinary skill in the art before the effective filling date of the claimed invention to have combined Vohra and Siddappa with the teachings of Singh to prevent attacks (see Singh pg. 2 left column paragraph 2 If the spy gets insufficient time to execute on the CPU, then the information leakage is reduced, stymieing the attack).
As per claim 2, Vohra, Siddappa, and Singh teach the computer-implemented method of Claim 1. Vohra teaches wherein the environmental information includes a status of one or more hardware resources within the HCI system ([0157] Readers will appreciate that the various components depicted in FIG. 3B may be grouped into one or more optimized computing packages as converged infrastructures. Such converged infrastructures may include pools of computers, storage and networking resources that can be shared by multiple applications and managed in a collective manner using policy-driven processes. Such converged infrastructures may minimize compatibility issues between various components within the storage system 306 while also reducing various costs associated with the establishment and operation of the storage system 306. Such converged infrastructures may be implemented with a converged infrastructure reference architecture, with standalone appliances, with a software driven hyper-converged approach (e.g., hyper-converged infrastructures), or in other ways; [0185] The storage systems described above may alone, or in combination with other computing resources, serves as a network edge platform that combines compute resources, storage resources, networking resources; [0208] The cloud-based storage system (403) may be used to provide services similar to the services that may be provided by the storage systems described above; [0116] Such data analytics applications may be configured, for example, to receive telemetry data phoned home by the storage system 306. Such telemetry data may describe various operating characteristics of the storage system 306 and may be analyzed, for example, to determine the health of the storage system 306 ).
As per claim 3, Vohra, Siddappa, and Singh teach the computer-implemented method of Claim 1. Vohra teaches wherein a status of one or more hardware resources within the HCI system is provided by one or more monitoring elements, the one or more monitoring elements comprising monitoring software and/or hardware ([0148] the monitoring module monitors the performance of the could-based storage system 318; [0229] the monitoring module determines that the utilization of the local storage that is collectively provided by the cloud computing instances (424a, 424b, 424n) has reached a predetermined utilization threshold (e.g., 95%); [0157] Readers will appreciate that the various components depicted in FIG. 3B may be grouped into one or more optimized computing packages as converged infrastructures. Such converged infrastructures may include pools of computers, storage and networking resources that can be shared by multiple applications and managed in a collective manner using policy-driven processes. Such converged infrastructures may minimize compatibility issues between various components within the storage system 306 while also reducing various costs associated with the establishment and operation of the storage system 306. Such converged infrastructures may be implemented with a converged infrastructure reference architecture, with standalone appliances, with a software driven hyper-converged approach (e.g., hyper-converged infrastructures), or in other ways; [0208] The cloud-based storage system (403) may be used to provide services similar to the services that may be provided by the storage systems described above).
As per claim 4, Vohra, Siddappa, and Singh teach the computer-implemented method of Claim 1. Vohra teaches wherein the environmental information includes an indication of the need to perform the data recovery operations within the HCI system ([0279] In some implementations, the cloud-based storage system (1002) may be designed to recover from a data loss by scaling up the cloud architecture used to initially store the data to recover data more quickly than if the original cloud architecture were used; [0157] Readers will appreciate that the various components depicted in FIG. 3B may be grouped into one or more optimized computing packages as converged infrastructures. Such converged infrastructures may include pools of computers, storage and networking resources that can be shared by multiple applications and managed in a collective manner using policy-driven processes. Such converged infrastructures may minimize compatibility issues between various components within the storage system 306 while also reducing various costs associated with the establishment and operation of the storage system 306. Such converged infrastructures may be implemented with a converged infrastructure reference architecture, with standalone appliances, with a software driven hyper-converged approach (e.g., hyper-converged infrastructures), or in other ways; [0208] The cloud-based storage system (403) may be used to provide services similar to the services that may be provided by the storage systems described above).
As per claim 5, Vohra, Siddappa, and Singh teach the computer-implemented method of Claim 1. Vohra teaches wherein the environmental information includes an indication of system-side applications that are needed to perform the data recovery operations within the HCI system ([0144] As such, one or more modules of computer program instructions that are executing within the cloud-based storage system 318 (e.g., a monitoring module that is executing on its own EC2 instance) may be designed to handle the failure of one or more of the cloud computing instances 340a, 340b, 340n with local storage 330, 334, 338. In such an example, the monitoring module may handle the failure of one or more of the cloud computing instances 340a, 340b, 340n with local storage 330, 334, 338 by creating one or more new cloud computing instances with local storage, retrieving data that was stored on the failed cloud computing instances 340a, 340b, 340n from the cloud-based object storage 348, and storing the data retrieved from the cloud-based object storage 348 in local storage on the newly created cloud computing instances; [0303] the storage controller application (408) may receive a signal indicating the failure, where the storage controller application (408) may then initiate creation (1104) of the replacement; [0157] Readers will appreciate that the various components depicted in FIG. 3B may be grouped into one or more optimized computing packages as converged infrastructures. Such converged infrastructures may include pools of computers, storage and networking resources that can be shared by multiple applications and managed in a collective manner using policy-driven processes. Such converged infrastructures may minimize compatibility issues between various components within the storage system 306 while also reducing various costs associated with the establishment and operation of the storage system 306. Such converged infrastructures may be implemented with a converged infrastructure reference architecture, with standalone appliances, with a software driven hyper-converged approach (e.g., hyper-converged infrastructures), or in other ways; [0208] The cloud-based storage system (403) may be used to provide services similar to the services that may be provided by the storage systems described above).
As per claim 6, Vohra, Siddappa, and Singh teach the computer-implemented method of Claim 1. Vohra teaches wherein the environmental information includes a risk score determined for one or more applications running within the HCI system ([0212] In fact, in other embodiments where costs savings may be prioritized over performance demands, only a single cloud computing instance may exist that contains the storage controller application. In such an example, a controller failure may take more time to recover from as a new cloud computing instance that includes the storage controller application would need to be spun up rather than having an already created cloud computing instance take on the role of servicing I/O operations that would have otherwise been handled by the failed cloud computing instance; [0157] Readers will appreciate that the various components depicted in FIG. 3B may be grouped into one or more optimized computing packages as converged infrastructures. Such converged infrastructures may include pools of computers, storage and networking resources that can be shared by multiple applications and managed in a collective manner using policy-driven processes. Such converged infrastructures may minimize compatibility issues between various components within the storage system 306 while also reducing various costs associated with the establishment and operation of the storage system 306. Such converged infrastructures may be implemented with a converged infrastructure reference architecture, with standalone appliances, with a software driven hyper-converged approach (e.g., hyper-converged infrastructures), or in other ways; [0208] The cloud-based storage system (403) may be used to provide services similar to the services that may be provided by the storage systems described above).
Additionally, Singh teaches a risk score determined for one or more applications by security monitoring software that intercepts and parses data output and input by the one or more applications (Section 2.2 paragraph 1 Most modern processors have a Performance Monitoring Unit on-chip to monitor micro-architectural events of running applications. Each logical core has a dedicated set of 4 to 8 configurable registers that can count the number of times a particular event occurs in a given duration. These registers are called Hardware Performance Counters (HPCs) and can be used to monitor a wide range of events like CPU-cycles, cache accesses, context-switches, and page faults; pg. 2 left column paragraph 3 it uses the HPCs to quantify the malicious behavior of each thread in the system using a metric called threat index).
As per claim 7, Vohra, Siddappa, and Singh teach the computer-implemented method of Claim 1. Vohra teaches comprising, in response to determining that the environmental information includes an indication that a new hardware storage resource has been added to the HCI system, increasing resources allocated to one or more applications within the HCI system until a building of data on the new hardware storage resource is completed ([0144] As such, one or more modules of computer program instructions that are executing within the cloud-based storage system 318 (e.g., a monitoring module that is executing on its own EC2 instance) may be designed to handle the failure of one or more of the cloud computing instances 340a, 340b, 340n with local storage 330, 334, 338. In such an example, the monitoring module may handle the failure of one or more of the cloud computing instances 340a, 340b, 340n with local storage 330, 334, 338 by creating one or more new cloud computing instances with local storage, retrieving data that was stored on the failed cloud computing instances 340a, 340b, 340n from the cloud-based object storage 348, and storing the data retrieved from the cloud-based object storage 348 in local storage on the newly created cloud computing instances; [0157] Readers will appreciate that the various components depicted in FIG. 3B may be grouped into one or more optimized computing packages as converged infrastructures. Such converged infrastructures may include pools of computers, storage and networking resources that can be shared by multiple applications and managed in a collective manner using policy-driven processes. Such converged infrastructures may minimize compatibility issues between various components within the storage system 306 while also reducing various costs associated with the establishment and operation of the storage system 306. Such converged infrastructures may be implemented with a converged infrastructure reference architecture, with standalone appliances, with a software driven hyper-converged approach (e.g., hyper-converged infrastructures), or in other ways; [0208] The cloud-based storage system (403) may be used to provide services similar to the services that may be provided by the storage systems described above).
As per claim 8, Vohra, Siddappa, and Singh teach the computer-implemented method of Claim 1. Vohra teaches wherein the data recovery operations include erasure coding based rebuilding of data of one or more failed hardware storage resources ([0147] Consider an example in which 1000 cloud computing instances are needed in order to locally store all valid data that users of the cloud-based storage system 318 have written to the cloud-based storage system 318. In such an example, assume that all 1,000 cloud computing instances fail. In such an example, the monitoring module may cause 100,000 cloud computing instances to be created, where each cloud computing instance is responsible for retrieving, from the cloud-based object storage 348, distinct 1/100,000th chunks of the valid data that users of the cloud-based storage system 318 have written to the cloud-based storage system 318 and locally storing the distinct chunk of the dataset that it retrieved. In such an example, because each of the 100,000 cloud computing instances can retrieve data from the cloud-based object storage 348 in parallel, the caching layer may be restored 100 times faster as compared to an embodiment where the monitoring module only create 1000 replacement cloud computing instances. In such an example, over time the data that is stored locally in the 100,000 could be consolidated into 1,000 cloud computing instances and the remaining 99,000 cloud computing instances could be terminated.).
As per claim 9, Vohra, Siddappa, and Singh teach the computer-implemented method of Claim 1. Vohra teaches wherein in response to determining that updated environmental information includes determination that the data recovery operations have been completed within the HCI system, additional merged resources allocated to the one or more system-side applications that performed the data recovery operations within the HCI system are removed ([0227] Consider an example in which 1000 cloud computing instances are needed in order to locally store all valid data that users of the cloud-based storage system (403) have written to the cloud-based storage system (403). In such an example, assume that all 1,000 cloud computing instances fail. In such an example, the monitoring module may cause 100,000 cloud computing instances to be created, where each cloud computing instance is responsible for retrieving, from the cloud-based object storage (432), distinct 1/100,000.sup.th chunks of the valid data that users of the cloud-based storage system (403) have written to the cloud-based storage system (403) and locally storing the distinct chunk of the dataset that it retrieved. In such an example, because each of the 100,000 cloud computing instances can retrieve data from the cloud-based object storage (432) in parallel, the caching layer may be restored 100 times faster as compared to an embodiment where the monitoring module only create 1000 replacement cloud computing instances. In such an example, over time the data that is stored locally in the 100,000 could be consolidated into 1,000 cloud computing instances and the remaining 99,000 cloud computing instances could be terminated; [0157] Readers will appreciate that the various components depicted in FIG. 3B may be grouped into one or more optimized computing packages as converged infrastructures. Such converged infrastructures may include pools of computers, storage and networking resources that can be shared by multiple applications and managed in a collective manner using policy-driven processes. Such converged infrastructures may minimize compatibility issues between various components within the storage system 306 while also reducing various costs associated with the establishment and operation of the storage system 306. Such converged infrastructures may be implemented with a converged infrastructure reference architecture, with standalone appliances, with a software driven hyper-converged approach (e.g., hyper-converged infrastructures), or in other ways; [0208] The cloud-based storage system (403) may be used to provide services similar to the services that may be provided by the storage systems described above).
As per claim 11, Vohra, Siddappa, and Singh teach the computer-implemented method of Claim 1. Vohra teaches the amount of the merged resources currently allocated to the second user-side application is reduced within the HCI system for minimizing an amount of negative activity within the HCI system thereby improving a performance of the HCI system ([0149] if the pool of local storage that is offered by the cloud computing instances is unnecessarily large, data can be consolidated and some cloud computing instances can be terminated; [0209] The cloud computing instances (404, 406) may be embodied, for example, as instances of cloud computing resources (e.g., virtual machines); [0332] removing unnecessary resources from the storage pool (1424) in order to save costs; [0157] Readers will appreciate that the various components depicted in FIG. 3B may be grouped into one or more optimized computing packages as converged infrastructures. Such converged infrastructures may include pools of computers, storage and networking resources that can be shared by multiple applications and managed in a collective manner using policy-driven processes. Such converged infrastructures may minimize compatibility issues between various components within the storage system 306 while also reducing various costs associated with the establishment and operation of the storage system 306. Such converged infrastructures may be implemented with a converged infrastructure reference architecture, with standalone appliances, with a software driven hyper-converged approach (e.g., hyper-converged infrastructures), or in other ways; [0208] The cloud-based storage system (403) may be used to provide services similar to the services that may be provided by the storage systems described above).
Additionally, Singh teaches wherein in response to determining that a risk score for a second user-side application exceeds a predetermined threshold, the second user-side application is identified as risky and the amount of the resources currently allocated to the second user-side application is reduced for minimizing an amount of negative activity that the second user-side application is capable of performing thereby improving a performance (pg. 2 left column paragraph 3 A high value of threat index indicates that the process gets less CPU time; pg. 3 left column paragraph 2 LEASH, similarly uses HPCs to compute a threat index for a thread. Threads which depict a micro-architectural attack like behavior are given a high threat index and are throttled by reducing their CPU time; pg. 2 left column paragraph 2 LEASH makes use of the observation that a spy thread in a micro-architectural attack needs to contend with the victim for a shared resource. The success of the attack depends on the extent to which the spy can force this contention. If the spy gets insufficient time to execute on the CPU, then the information leakage is reduced, stymieing the attack; Section 2.2 paragraph 1 Most modern processors have a Performance Monitoring Unit on-chip to monitor micro-architectural events of running applications. Each logical core has a dedicated set of 4 to 8 configurable registers that can count the number of times a particular event occurs in a given duration. These registers are called Hardware Performance Counters (HPCs) and can be used to monitor a wide range of events like CPU-cycles, cache accesses, context-switches, and page faults; Section 2.2 paragraph 2 detecting anomalous behavior in programs).
As per claim 12, Vohra, Siddappa, and Singh teach the computer-implemented method of Claim 11. Singh teaches wherein the amount of the merged resources no longer allocated to the second user-side application in response to determining that the risk score for the second user-side application exceeds the predetermined threshold is allocated to one or more other applications having the risk score below the predetermined threshold, wherein in response to determining that the risk score for the second user-side application no longer exceeds the predetermined threshold, the second user-side application is no longer identified as risky, and the amount of the merged resources is returned to the second user-side application (pg. 4 left column paragraph 1 LEASH uses HPCs to detect such anomalous behavior and penalizes such threads by decreasing their weight, which in turn reduces their timeslice (Equation 1). If the thread stops exhibiting the anomalous behavior, its weight is gradually increased, thus regaining its regular timeslice; pg. 5 left column paragraph 3 In our evaluation platform, γ = 0.1 which means that, for every rise in threat index values, the weight drops by 10% until it reaches wMIN. Similarly, when a thread is recovering, the threat index value is negative and hence every fall in threat index value increases its weight by 10% until its weight is restored. The adaptable design of LEASH efficiently brings down the cost of a false penalization. Once a benign thread, which is erroneously flagged, is unflagged, it regains its CPU share; Section 2.2 paragraph 1 Most modern processors have a Performance Monitoring Unit on-chip to monitor micro-architectural events of running applications. Each logical core has a dedicated set of 4 to 8 configurable registers that can count the number of times a particular event occurs in a given duration. These registers are called Hardware Performance Counters (HPCs) and can be used to monitor a wide range of events like CPU-cycles, cache accesses, context-switches, and page faults; Section 2.2 paragraph 2 detecting anomalous behavior in programs).
As per claim 13, it is a computer program product claim of claim 1, so it is rejected for similar reasons. Additionally, Vohra teaches a computer program product comprising: one or more computer readable storage media; and program instructions stored on the one or more computer readable storage media to perform operations comprising ([0341] These computer readable program instructions may also be stored in a computer readable storage medium that can direct a computer, a programmable data processing apparatus, and/or other devices to function in a particular manner).
As per claim 14, Vohra, Siddappa, and Singh teach the computer program product of Claim 13. Vohra teaches wherein the environmental information includes a status of one or more hardware resources within the HCI system, wherein the amount of the merged resources allocated to the one or more system-side applications are running within the HCI system needed to perform the data recovery operations within the HCI system is retrieved from a portion of the merged resources held in reserve within the HCI system ([0288] In this example cloud storage architecture of the cloud-based storage system (1002), recovery from data loss may be implemented in multiple ways. As one example, within the non-durable cloud storage layer (1004), one or more of the cloud computing instances (424a-424n) may fail, or portions of storage (414, 426 . . . 422, 430) for one or more of the cloud computing instances (424a-424n) may fail; [0213] The cloud computing instances (424a, 424b, 424n) with local storage (414, 418, 422) may be embodied, for example, as EC2 M5 instances that include one or more SSDs, as EC2 R5 instances that include one or more SSDs, as EC2 13 instances that include one or more SSDs, and so on. In some embodiments, the local storage (414, 418, 422) must be embodied as solid-state storage (e.g., SSDs); [0292] loss of one or more cloud computing instances, such as the loss of cloud computing instance (424a); [0157] Readers will appreciate that the various components depicted in FIG. 3B may be grouped into one or more optimized computing packages as converged infrastructures. Such converged infrastructures may include pools of computers, storage and networking resources that can be shared by multiple applications and managed in a collective manner using policy-driven processes. Such converged infrastructures may minimize compatibility issues between various components within the storage system 306 while also reducing various costs associated with the establishment and operation of the storage system 306. Such converged infrastructures may be implemented with a converged infrastructure reference architecture, with standalone appliances, with a software driven hyper-converged approach (e.g., hyper-converged infrastructures), or in other ways; [0208] The cloud-based storage system (403) may be used to provide services similar to the services that may be provided by the storage systems described above; [0144] As such, one or more modules of computer program instructions that are executing within the cloud-based storage system 318 (e.g., a monitoring module that is executing on its own EC2 instance) may be designed to handle the failure of one or more of the cloud computing instances 340a, 340b, 340n with local storage 330, 334, 338. In such an example, the monitoring module may handle the failure of one or more of the cloud computing instances 340a, 340b, 340n with local storage 330, 334, 338 by creating one or more new cloud computing instances with local storage, retrieving data that was stored on the failed cloud computing instances 340a, 340b, 340n from the cloud-based object storage 348, and storing the data retrieved from the cloud-based object storage 348 in local storage on the newly created cloud computing instances; [0240] Readers will appreciate that, in an effort to increase the resiliency of the cloud-based storage systems described above, various components may be located within different availability zones. For example, a first cloud computing instance that supports the execution of the storage controller application may be located within a first availability zone while a second cloud computing instance that also supports the execution of the storage controller application may be located within a second availability zone. Likewise, the cloud computing instances with local storage may be distributed across multiple availability zones. In fact, in some embodiments, an entire second cloud-based storage system could be created in a different availability zone, where data in the original cloud-based storage system is replicated (synchronously or asynchronously) to the second cloud-based storage system so that if the entire original cloud-based storage system went down, a replacement cloud-based storage system (the second cloud-based storage system) could be brought up in a trivial amount of time.).
As per claim 15, it is a computer program product of claim 3, so it is rejected for similar reasons.
As per claim 16, it is a computer program product of claim 4, so it is rejected for similar reasons.
As per claim 17, it is a computer program product of claim 5, so it is rejected for similar reasons.
As per claim 18, Vohra, Siddappa, and Singh teach the computer program product of Claim 13. Vohra teaches wherein the environmental information includes a risk score determined for one or more applications running within the HCI system ([0212] In fact, in other embodiments where costs savings may be prioritized over performance demands, only a single cloud computing instance may exist that contains the storage controller application. In such an example, a controller failure may take more time to recover from as a new cloud computing instance that includes the storage controller application would need to be spun up rather than having an already created cloud computing instance take on the role of servicing I/O operations that would have otherwise been handled by the failed cloud computing instance; [0157] Readers will appreciate that the various components depicted in FIG. 3B may be grouped into one or more optimized computing packages as converged infrastructures. Such converged infrastructures may include pools of computers, storage and networking resources that can be shared by multiple applications and managed in a collective manner using policy-driven processes. Such converged infrastructures may minimize compatibility issues between various components within the storage system 306 while also reducing various costs associated with the establishment and operation of the storage system 306. Such converged infrastructures may be implemented with a converged infrastructure reference architecture, with standalone appliances, with a software driven hyper-converged approach (e.g., hyper-converged infrastructures), or in other ways; [0208] The cloud-based storage system (403) may be used to provide services similar to the services that may be provided by the storage systems described above).
As per claim 19, Vohra, Siddappa, and Singh teach the computer program product of Claim 18. Singh teaches comprising, in response to determining that the risk score for a first application of the one or more applications exceeds a predetermined threshold, identifying the first application of the one or more applications as risky; and reducing the amount of the merged resources currently allocated to the first application of the one or more applications (pg. 2 left column paragraph 3 A high value of threat index indicates that the process gets less CPU time; pg. 3 left column paragraph 2 LEASH, similarly uses HPCs to compute a threat index for a thread. Threads which depict a micro-architectural attack like behavior are given a high threat index and are throttled by reducing their CPU time).
As per claim 20, Vohra, Siddappa, and Singh teach the computer program product of 13. Vohra teaches wherein in response to determining that the environmental information indicates the need to perform the data recovery operations within the HCI system, the amount of the resources currently allocated to the one or more system-side applications needed to perform the data recovery operations within the HCI system is increased by allocating additional resources thereto ([0144] As such, one or more modules of computer program instructions that are executing within the cloud-based storage system 318 (e.g., a monitoring module that is executing on its own EC2 instance) may be designed to handle the failure of one or more of the cloud computing instances 340a, 340b, 340n with local storage 330, 334, 338. In such an example, the monitoring module may handle the failure of one or more of the cloud computing instances 340a, 340b, 340n with local storage 330, 334, 338 by creating one or more new cloud computing instances with local storage, retrieving data that was stored on the failed cloud computing instances 340a, 340b, 340n from the cloud-based object storage 348, and storing the data retrieved from the cloud-based object storage 348 in local storage on the newly created cloud computing instances; [0157] Readers will appreciate that the various components depicted in FIG. 3B may be grouped into one or more optimized computing packages as converged infrastructures. Such converged infrastructures may include pools of computers, storage and networking resources that can be shared by multiple applications and managed in a collective manner using policy-driven processes. Such converged infrastructures may minimize compatibility issues between various components within the storage system 306 while also reducing various costs associated with the establishment and operation of the storage system 306. Such converged infrastructures may be implemented with a converged infrastructure reference architecture, with standalone appliances, with a software driven hyper-converged approach (e.g., hyper-converged infrastructures), or in other ways; [0208] The cloud-based storage system (403) may be used to provide services similar to the services that may be provided by the storage systems described above; [0279] In some implementations, the cloud-based storage system (1002) may be designed to recover from a data loss by scaling up the cloud architecture used to initially store the data to recover data more quickly than if the original cloud architecture were used.).
As per claim 21, Vohra, Siddappa, and Singh teach the computer program product of Claim 20. Vohra teaches wherein in response to determining that updated environmental information includes determination that the data recovery operations have been completed within the HCI system, additional merged resources allocated to the one or more system-side applications that performed the data recovery operations within the HCI system are removed ([0227] Consider an example in which 1000 cloud computing instances are needed in order to locally store all valid data that users of the cloud-based storage system (403) have written to the cloud-based storage system (403). In such an example, assume that all 1,000 cloud computing instances fail. In such an example, the monitoring module may cause 100,000 cloud computing instances to be created, where each cloud computing instance is responsible for retrieving, from the cloud-based object storage (432), distinct 1/100,000.sup.th chunks of the valid data that users of the cloud-based storage system (403) have written to the cloud-based storage system (403) and locally storing the distinct chunk of the dataset that it retrieved. In such an example, because each of the 100,000 cloud computing instances can retrieve data from the cloud-based object storage (432) in parallel, the caching layer may be restored 100 times faster as compared to an embodiment where the monitoring module only create 1000 replacement cloud computing instances. In such an example, over time the data that is stored locally in the 100,000 could be consolidated into 1,000 cloud computing instances and the remaining 99,000 cloud computing instances could be terminated; [0157] Readers will appreciate that the various components depicted in FIG. 3B may be grouped into one or more optimized computing packages as converged infrastructures. Such converged infrastructures may include pools of computers, storage and networking resources that can be shared by multiple applications and managed in a collective manner using policy-driven processes. Such converged infrastructures may minimize compatibility issues between various components within the storage system 306 while also reducing various costs associated with the establishment and operation of the storage system 306. Such converged infrastructures may be implemented with a converged infrastructure reference architecture, with standalone appliances, with a software driven hyper-converged approach (e.g., hyper-converged infrastructures), or in other ways; [0208] The cloud-based storage system (403) may be used to provide services similar to the services that may be provided by the storage systems described above).
Additionally, Siddappa teaches reallocated to the other applications from which the additional resources were retrieved ([0048] After the resource configurer 178 has completed the process of association/disassociation described above, the workload categorizer 180 re-categorizes the affected offering workload and needy workload involved in the resource lending transaction, if needed, and the process/method returns to again poll the network resources (at the block 602); [0024] In some examples, the workload selector 182 upon selecting a needy workload to receive additional resources (either based on the neediness of the workload or based on a request for resources from the needy workload) from an offering workload will identify an amount of additional resources that are needed. The workload selector 182 may identify the amount of additional resources that are needed based on information supplied by needy workload and/or based on a statistical analysis of the resources currently being consumed versus an amount of resources currently allotted to the needy workload. In some examples, the needy workload, upon consuming a threshold amount of allotted resources, may identify a need for additional resources to the workload selector 182. The threshold amount can be determined based on a static value or on a dynamic analysis of the resources being consumed across multiple workloads. The workload selector 182 then selects one of the offering workloads to lend resources to the needy workload. In some examples, the workload selector notifies the example resource configurer 178 that the amount of identified resources are to be lent from the selected offering workload to the needy workload).
As per claim 22, Vohra, Siddappa, and Singh teach the computer program product of Claim 13. Singh teaches wherein in response to determining that the environmental information includes the existence of the security threat associated with a plurality of user-side applications, the amount of the merged resources currently allocated to the plurality of user-side applications is reduced (Section 2.2 paragraph 1 Most modern processors have a Performance Monitoring Unit on-chip to monitor micro-architectural events of running applications. Each logical core has a dedicated set of 4 to 8 configurable registers that can count the number of times a particular event occurs in a given duration. These registers are called Hardware Performance Counters (HPCs) and can be used to monitor a wide range of events like CPU-cycles, cache accesses, context-switches, and page faults; pg. 3 left column paragraph 2 LEASH, similarly uses HPCs to compute a threat index for a thread. Threads which depict a micro-architectural attack like behavior are given a high threat index and are throttled by reducing their CPU time; pg. 3 4. The LEASH Framework paragraph 1 Micro-architectural attacks depend considerably on CPU resources. If the attack programs are starved of the CPU, the success drops considerably; Fig. 1a caption LEASH stymies micro-architectural attacks by detecting malicious behavior in programs and reducing its CPU-share, thereby reducing the leakage from the shared resource; Section 1 paragraph 2 In a typical micro-architectural attack, the attacker runs a program called the spy that contends with a victim program for shared hardware resources).
As per claim 23, it is a system claim of claim 1. Additionally, Vohra teaches a system comprising: a processor set; one or more computer readable storage media; and program instructions stored on the one or more computer readable storage media to cause the processor set to perform operations comprising ([0336] Embodiments can include be a system, a method, and/or a computer program product. The computer program product may include a computer readable storage medium (or media) having computer readable program instructions thereon for causing a processor to carry out aspects of the present disclosure; [0045] processors implementing a combination of instruction sets.).
As per claim 27, Vohra, Siddappa, and Singh teach the system of Claim 23. Vohra teaches wherein the environmental information includes a status of one or more hardware resources within the HCI system ([0095] A continuous monitoring system correlates hardware and software status and the hardware identifiers; [0157] Such converged infrastructures may be implemented with a converged infrastructure reference architecture, with standalone appliances, with a software driven hyper-converged approach (e.g., hyper-converged infrastructures), or in other ways.).
As per claim 28, Vohra, Siddappa, and Singh teach the system of Claim 23. Vohra teaches wherein a status of one or more hardware resources within the HCI system is provided by one or more monitoring elements, the one or more monitoring elements comprising monitoring software and/or hardware ([0095] A continuous monitoring system correlates hardware and software status and the hardware identifiers; [0157] Such converged infrastructures may be implemented with a converged infrastructure reference architecture, with standalone appliances, with a software driven hyper-converged approach (e.g., hyper-converged infrastructures), or in other ways.).
As per claim 29, Vohra, Siddappa, and Singh teach the system of Claim 23. Vohra teaches wherein the environmental information includes an indication of the need to perform the data recovery operations within the HCI system ([0288] In this example cloud storage architecture of the cloud-based storage system (1002), recovery from data loss may be implemented in multiple ways. As one example, within the non-durable cloud storage layer (1004), one or more of the cloud computing instances (424a-424n) may fail, or portions of storage (414, 426 . . . 422, 430) for one or more of the cloud computing instances (424a-424n) may fail; [0144] As such, one or more modules of computer program instructions that are executing within the cloud-based storage system 318 (e.g., a monitoring module that is executing on its own EC2 instance) may be designed to handle the failure of one or more of the cloud computing instances 340a, 340b, 340n with local storage 330, 334, 338. In such an example, the monitoring module may handle the failure of one or more of the cloud computing instances 340a, 340b, 340n with local storage 330, 334, 338 by creating one or more new cloud computing instances with local storage, retrieving data that was stored on the failed cloud computing instances 340a, 340b, 340n from the cloud-based object storage 348, and storing the data retrieved from the cloud-based object storage 348 in local storage on the newly created cloud computing instances; [0157] Such converged infrastructures may be implemented with a converged infrastructure reference architecture, with standalone appliances, with a software driven hyper-converged approach (e.g., hyper-converged infrastructures), or in other ways)
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to HSING CHUN LIN whose telephone number is (571)272-8522. The examiner can normally be reached Mon - Fri 9AM-5PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Aimee Li can be reached at (571) 272-4169. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/H.L./Examiner, Art Unit 2195 /Aimee Li/Supervisory Patent Examiner, Art Unit 2195