DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant’s remarks, see page 10, filed 06/10/2026 with regard to the priority issues identified in pages 8-9 of the Non-Final Rejection mailed 02/10/2026, have been fully acknowledged. Applicant states, “Since the office action's suggestion in this regard does not seem to affect patentability of claim 28, the applicant reserves further comment”. Therefore, the Examiner defers to the rejection below as a response to these remarks.
Applicant’s remarks, see pages 10-11, filed 06/10/2026 with respect to the objection to the drawings have been fully considered. The previous objection to the drawings has been withdrawn in response to the new drawings filed 06/10/2026.
Applicant’s arguments filed 06/10/2026, see page 11, with respect to the rejection of claims 26-28 under 35 U.S.C. § 112(a) have been fully considered. These rejections have been withdrawn in response to the removal of the limitation “an activity monitor configured to detect security and compliance violations” from claim 26.
Applicant’s arguments/amendments filed 06/10/2026, see page 11, with respect to the rejection of claims 1-2, 4-6, 15-17 and 19-28 under 35 U.S.C. § 112(b) have been fully considered. The rejections regarding the limitations “a corresponding one of the realms with which the computer-based endpoint agent is registered”, “processing facilities to comply with the data protection or privacy restrictions for a corresponding one of the realms with which the computer-based endpoint agent is registered”, “such that computer-based memory stores a unique identifier for each specific one of the endpoint devices in logical association with a unique identifier for the corresponding one of the realms”, “a plurality of user endpoint devices geographically distributed relative to one another such that at least one of the endpoint devices is subject to a first set of data protection or privacy restrictions associated with a first realm of the plurality of realms different from a second set of data protection or privacy restrictions for other endpoint devices associated with a second realm of the plurality of realms”, “such that at least one of the endpoint devices is subject to a first set of data protection or privacy restrictions associated with a first realm of the plurality of realms different from a second set of data protection or privacy restrictions for other endpoint devices associated with a second realm of the plurality of realms”, and “the human system administrator” of claims 1 and 21 as presented in the Non-Final Rejection mailed 02/10/2026 (see pages 11-13) have been withdrawn.
The rejections under 35 U.S.C. § 112(b) regarding the limitations “wherein the alert made available on the computer network to the human system administrator is accompanied by one or more of the screenshots that were stored in the cloud storage device and associated with metadata from a triggering user activity” in claim 21, and “the method further comprising” in claim 27 have been maintained.
Applicant's arguments, see pages 11-17 filed 06/10/2026, with respect to the rejection of claims 1-2, 4-6, 15-17 and 19-28 under 35 U.S.C. § 103 have been fully considered but they are not persuasive.
Applicant first argues that the limitation, “each endpoint is registered with a corresponding one of the plurality of realms such that the endpoint device is associated with a corresponding realm definition” is not taught by the Mahaffey or Gupta references, and that “determining an EPG and retrieving policies associated with the EPG is not the same as registering an endpoint agent with a realm such that the endpoint device becomes associated with a corresponding stored realm definition, as featured in claim 1. The Office Action has not identified where Gupta discloses registration of an endpoint agent with a realm, nor where Gupta discloses that such registration associates the endpoint device with a stored realm definition”.
The Examiner respectfully disagrees.
In the Non-Final Rejection mailed 02/10/2026 (see pages 4-6), this argument was already addressed and fully responded to, and once more Applicant here makes the conclusory argument that “determining an EPG and retrieving policies associated with the EPG is not the same as registering an endpoint agent with a realm”, despite Gupta paragraph [0091] explicitly teaching “The policies may be mapped to specific provisions of regulations or standards (e.g., FIG. 3), and the policies can be applicable to an endpoint or a collection of endpoints (i.e., an EPG). In some example embodiments, the network can determine applicable policies for traffic by determining a source EPG and destination EPG and retrieving the applicable policies based on the source EPG and destination EPG. In some example embodiments, the network can dynamically determine an EPG associated with traffic based on a state of a host and/or endpoint, process, or user corresponding to the traffic”. In the Gupta reference, EPGs stand for endpoint groups (“In various example embodiments, networks can employ dynamic policies based on the state of a host and/or endpoint, process, and/or user associated with a flow. Networks can initially associate traffic with a first endpoint group (EPG) and then reassign traffic to one or more second EPGs if a host and/or endpoint state, process state, or user state changes” Gupta [0017]). After full consideration, the Examiner re-affirms the position that the broadest reasonable interpretation of “each endpoint is registered with a corresponding one of the plurality of realms such that the endpoint device is associated with a corresponding realm definition” is met by the Gupta reference by Gupta teaching the retrieval of the applicable policies for the endpoint devices by the network, evidenced by the broad definition of the realms. Applicant’s own originally filed disclosure discloses such a claimed “registration” as sending data to a registry in page 22 and Fig. 5C. Therefore, the Gupta reference teaching the network looking at endpoints to retrieve the applicable policies renders obvious the previously claimed “wherein each endpoint is registered with a corresponding one of the realms of the plurality of realms”.
Applicant next argues that neither Mahaffey nor Gupta disclose or render obvious “the corresponding realm definition identifies one or more of the plurality of data processing facilities as permissible destinations, under applicable data protection or privacy restrictions, for telemetry data transmitted by the endpoint agent” and that “However, the cited portions of Gupta do not teach or suggest a stored realm definition that identifies permissible telemetry- processing destinations for an endpoint agent. Nor do those cited portions of Gupta teach or suggest transmitting endpoint telemetry to a selected processing facility in compliance with such a realm definition”.
The Examiner respectfully disagrees.
Here, the Applicant once more as in the remarks filed 10/15/2025, is seeking a per se recitation of the exact claim language and readily admits on the record “Gupta's policies regulate communications, access permissions, compliance enforcement, and EPG behavior. (Gupta 0051-0055, 0069-0071, 0091.)” on page 13 of the remarks. It is clear that the disclosure of Gupta renders obvious communications regulations, access permission, and most importantly, compliance enforcement as readily admitted by the Applicant. The Applicant does not adequately describe how the claimed invention is different from the reference and instead elects to repeat the per se claim language, followed by the conclusory argument that “However, the cited portions of Gupta do not teach or suggest a stored realm definition that identifies permissible telemetry- processing destinations for an endpoint agent. Nor do those cited portions of Gupta teach or suggest transmitting endpoint telemetry to a selected processing facility in compliance with such a realm definition. The Office Action therefore has not shown where Gupta teaches or suggests the claimed realm-definition architecture governing permissible telemetry-processing destinations, as represented in the claim language”. The claimed “realm” is clearly anticipated and/or rendered obvious by disclosing any of partitioning, grouping, identifying a subsection of a network, or grouping of endpoints (endpoint groups disclosed by Gupta; and Applicant’s own disclosure at page 25 states that the disclosed techniques enable grouping of endpoints under “realms”). The claimed “realm definition” is clearly anticipated and/or rendered obvious by information, data, or configurations pertaining to policies, rules, regulations, compliance, and/or restrictions that are adhered to or practiced by devices in the “realm”.
Applicant then argues that claim 20 is allowable because Mahaffey allegedly does not disclose collecting and transmitting one or more screenshots.
The Examiner respectfully disagrees.
Mahaffey [0222] clearly discloses the notification modules 607 and 657 being configured to generate one or more user interface components, and such user interface components may be a graphical icon, color-coded image, or display automatically generated text descriptive of a SNC connection status. The Examiner respectfully submits that the claimed “screenshots” under the broadest reasonable interpretation, in light of the high level of generality recited in the originally filed specification, is anticipated and/or rendered obvious by disclosure of image/graphical data collection/transmission, data activity tracking and/or logging, and/or metadata collection/transmission/association. Mahaffey explicitly disclosing a notification module generating one or more user interface components that may comprise graphical icons, and that the graphical icon may be a color-coded image or display automatically generated descriptive text, renders obvious the claim limitation at issue.
Applicant finally argues that claim 21 is allowable because Mahaffey allegedly does not amount to “one or more of the screenshots from the corresponding endpoint device where the user activity occurred and that were transmitted to the cloud storage device for storage”.
The Examiner respectfully disagrees.
Claim 21 recites that the claimed alert is accompanied by one or more of the screenshots from the corresponding endpoint devices where the user activity occurred and that were transmitted to cloud storage device for storage. The Examiner first notes that the claim recites an intended use of “for storage” and that a recitation of the intended use of the claimed invention must result in a structural difference between the claimed invention and the prior art in order to patentably distinguish the claimed invention from the prior art. If the prior art structure is capable of performing the intended use, then it meets the claim. Secondly, in the Non-Final Rejection mailed 02/10/2026, the limitations at issue were mapped to paragraphs [0222-0223], [0377], and [0290-0292] of the Mahaffey reference. As discussed above, the claimed “screenshots” under the broadest reasonable interpretation, in light of the high level of generality recited in the originally filed specification, is anticipated and/or rendered obvious by disclosure of image/graphical data collection/transmission, data activity tracking and/or logging, and/or metadata collection/transmission/association (of which Mahaffey explicitly discloses or teaches at least a notification module generating one or more user interface components that may comprise graphical icons, and that the graphical icon may be a color-coded image or display automatically generated descriptive text). Applicant’s argument that “Nor does the office action explain why a contrary conclusion might be appropriate” is inaccurate as these reasonings were described at least in pages 7-8 of the Non-Final Rejection mailed 02/10/2026 “Response to Arguments”. Applicant’s remarks amount to relying upon the prior art references not utilizing the exact per se claim language, which is improper as the pending claims are to be given their broadest reasonable interpretation in light of the specification.
Priority
Applicant’s claim for the benefit of a prior-filed application under 35 U.S.C. 119(e) or under 35 U.S.C. 120, 121, 365(c), or 386(c) is acknowledged. Applicant has not complied with one or more conditions for receiving the benefit of an earlier filing date under 35 U.S.C. 119(d) as follows:
The later-filed application must be an application for a patent for an invention which is also disclosed in the prior application (the parent or original nonprovisional application or provisional application). The disclosure of the invention in the parent application and in the later-filed application must be sufficient to comply with the requirements of 35 U.S.C. 112(a) or the first paragraph of pre-AIA 35 U.S.C. 112, except for the best mode requirement. See Transco Products, Inc. v. Performance Contracting, Inc., 38 F.3d 551, 32 USPQ2d 1077 (Fed. Cir. 1994).
The disclosure of the prior-filed application, provisional application 62/903,828, fails to provide adequate support or enablement in the manner provided by 35 U.S.C. 112(a) or pre-AIA 35 U.S.C. 112, first paragraph for one or more claims of this application. In particular, the prior-filed application’s specification fails to provide adequate support for the content of dependent claim 28 and newly claimed dependent claim 29, and therefore the effective filing date of dependent claims 28-29 are the domestic benefit date of PCT/US20/51739 (09/21/2020).
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 07/24/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Drawings
The drawings were received on 06/10/2026. These drawings are acceptable.
Claim Objections
Claim 4 and 21 are objected to because of the following informalities:
Claim 4 line 3, “contains” should read “contain”.
Claim 21 contains the phrase “along with associated with metadata from a triggering user activity” which is grammatically incorrect.
Appropriate correction is required.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 21 and 27 rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claim 21 recites the limitation “wherein the alert made available on the computer network is accompanied by one or more of the screenshots from the corresponding endpoint device where the user activity occurred and that were transmitted to the cloud storage device for storage, along with associated with metadata from a triggering user activity”. The recited function does not follow from the structure recited in the claim, so it is unclear whether the function requires some other structure or is simply a result of operating the “device” in a certain manner. Thus, one of ordinary skill in the art would not be able to draw a clear boundary between what is and is not covered by the claim. See MPEP 2173.05(g) for more information.
Claim 27 recites the limitation “the method further comprising”. There is insufficient antecedent basis for this limitation in the claim and renders the claim indefinite as it refers to a computer network and a method of use in the same claim.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-2, 4-6, 15-17 and 19-29 are rejected under 35 U.S.C. 103 as being unpatentable over Mahaffey et. al. (US Publication No. US 2015/0188949 A1) hereinafter Mahaffey in view of Gupta et. al. (US Publication No. US 2016/0359915 A1) hereinafter Gupta.
Regarding Claim 1:
Mahaffey discloses a computer network logically segmented into a plurality of realms (Mahaffey Fig. 1 computer network 100, [0036], Fig. 7, [0173-0175], and [0161-0163]), the network comprising: a plurality of user endpoint devices, wherein at least one of the endpoint devices is subject to a first set of data protection or privacy restrictions associated with a first realm of the plurality of realms different from a second set of data protection or privacy restrictions than other endpoint devices associated with a second realm of the plurality of realms (Mahaffey Fig. 13, [0161-0163], [0173-0175] may monitor device’s geographical context, [0310]); a plurality of data processing facilities coupled to the user endpoint devices over a network (Mahaffey [0210-0212] account manager 662 may handle load balancing amongst servers (data processing facilities)), wherein the data processing facilities are in different geographical regions (Mahaffey [0212] “account manager 662 may transfer SNC functionalities to another server based on a geographical parameter associated with a user or computing device… If computing device 601 moves to a second geographical region, account manager 662 may transfer the connection to an account creation server located in the second geographical region”); and a computer-based endpoint agent in each of the endpoint devices (Mahaffey Fig. 6; [0210-0212]), … and wherein each computer-based endpoint agent is configured to: collect telemetry data relating to user activity at its associated endpoint device (Mahaffey [0213-0216] “System 600 may include malware identifier 666, which may inspect network traffic flowing to and from computing device 601. Malware identifier 666 may be configured to identify attempts to exploit vulnerabilities of computing device 601 and applications 604 which may be installed and running on computing device 601. Malware identifier 666 may monitor traffic and identify malicious files and/or activities based on a predetermined list of filenames. Malware identifier 666 may also identify malicious files and/or activities based on detected behaviors.”); and transmit the collected telemetry data to a selected one of the plurality of data processing facilities in compliance with the corresponding realm definition (Mahaffey Fig. 13, [0173-0175] geographical context used to determine if a policy exists regarding security or privacy, [0212] functionality is transferred to different servers based on geographical parameters, [0310-0318] contextual information (such as location) used to determine presence or absence of security/privacy policies).
Mahaffey does not explicitly disclose wherein each endpoint agent is registered with a corresponding one of the plurality of realms such that the endpoint device is associated with a corresponding realm definition of a plurality of realm definitions stored in computer-based memory, wherein the corresponding realm definition identifies one or more of the plurality of data processing facilities as permissible destinations, under applicable data protection or privacy restrictions for telemetry data transmitted by the endpoint agent.
Gupta teaches wherein each endpoint agent is registered with a corresponding one of the plurality of realms such that the endpoint device is associated with a corresponding realm definition of a plurality of realm definitions stored in computer-based memory (Gupta [0051-0057] policies can be set based on endpoint group and compliance module provides for design/implementation/regulatory compliance to enforce the policies of the network; [0091] by looking at the endpoints the applicable policies can be retrieved), such that computer-based memory stores a unique identifier for each specific one of the endpoint devices in logical association with a unique identifier for the corresponding one of the realms (Gupta [0071] “The unique user identification requirement 344 dictates that each user who has access to protected electronic information has a unique identifier. In an example embodiment, the compliance module 212 can assign different users with a same identifier to a restricted EPG”), wherein the corresponding realm definition identifies one or more of the plurality of data processing facilities as permissible destinations, under applicable data protection or privacy restrictions for telemetry data transmitted by the endpoint agent (Gupta [0051-0057] policy builder based on network topology, [0069-0070] and Fig. 2 compliance module stores and defines policies to ensure compliance and allow/deny access, [0091] enforce policies based on source and destination endpoint groups).
It would have been obvious to one having ordinary skill in the art at before the time the invention was effective filed to combine the network disclosed by Mahaffey with the realm definitions taught by Gupta.
The motivation for this combination would be in order to greater accomplish the goal of data privacy/protection adherence by enabling the defining of sectors of the network that may fall under various sets of regulations. Adherence to the correct policies is seen as important by Mahaffey in [0345] where contextual information is analyzed to determine security policy compliance.
Regarding Claim 2:
The combination of Mahaffey and Gupta further teaches the computer network of claim 1 (Mahaffey Fig. 1 computer network 100, [0036]), wherein each data processing facility is configured to: analyze the telemetry data to identify potential insider threats posed by the user activity associated with the telemetry data (Mahaffey [0213] “malware identifier 666 may be configured to identify attempts to exploit vulnerabilities of computing device 601 and applications 604 which may be installed and running on computing device 601. Malware identifier 666 may monitor traffic and identify malicious files and/or activities based on a predetermined list of filenames. Malware identifier 666 may also identify malicious files and/or activities based on detected behaviors”); and create an alert if any such insider threat is identified (Mahaffey [0377] in response an alert may be sent (“e.g., via email, to a security alerting console, to a SIEM system”) amongst other actions taken).
Regarding Claim 4:
The combination of Mahaffey and Gupta further teaches the computer network of claim 1 (Mahaffey Fig. 1 computer network 100, [0036]), further comprising an agent data store in each of the endpoint devices (Mahaffey [0314-0315] contextual information can be stored and retrieved from one or more data stores), wherein each of the agent data stores contains data that identifies: one or more of the data processing facilities as being permissible destinations (Mahaffey [0391-399] routing policy can specify permissible routes), under applicable data protection or privacy restrictions (Mahaffey [0394-0396] routing policy can label traffic subject to policy implementations; map labels to routing policy, rule matching), for the telemetry data transmitted by an associated endpoint agent ([0310-0318] contextual information (such as location) used to determine presence or absence of security/privacy policies); and/or one or more routes through the network as being permissible routes (Mahaffey [0173-0175] geographical context used to determine if a policy exists regarding security or privacy, [0395-0398] different conditions influence the routes as being permissible or not), under applicable data protection or privacy restrictions (Mahaffey [0310-0318] contextual information (such as location) used to determine presence or absence of security/privacy policies), for the telemetry data transmitted by the associated endpoint agent to one of the permissible destination data processing facilities (Mahaffey [0212] proper server transferred to).
Regarding Claim 5:
The combination of Mahaffey and Gupta further teaches the computer network of claim 4 (Mahaffey Fig. 1 computer network 100, [0036]), wherein the endpoint agent in each endpoint device is configured to transmit the telemetry data to one of the identified permissible destination data processing facilities via one of the identified permissible routes though the network (Mahaffey [0395-0399] different conditions influence the routes as being permissible or not; routing policy may require certain routing actions and to satisfied before transmission).
Regarding Claim 6:
The combination of Mahaffey and Gupta further teaches the computer network of claim 5 (Mahaffey Fig. 1 computer network 100, [0036]), wherein the endpoint agents are configured to periodically receive updates regarding the permissible destination data processing facilities and/or the permissible routes through the network from a remote data store (Mahaffey [0399] routing actions and policies can change; [0203-0207] connection policies can be changed and updated; [0424] “changes may be applied to the routes, propagated or otherwise defined. And, as may be expected, routes may expire for a number of reasons, such as inactivity”).
Regarding Claim 15:
The combination of Mahaffey and Gupta further teaches the computer network of claim 1 (Mahaffey Fig. 1 computer network 100, [0036]), further comprising: computer-based memory storing the plurality of realm definitions (Gupta [0051] policy builder based on network topology, [0069-0070] and Fig. 2 compliance module stores and defines policies to ensure compliance and allow/deny access), wherein each realm definition identifies one or more of the plurality of data processing facilities in the computer network as permissible destinations (Gupta [0040], [0070] which traffic is allowed or denied depending on endpoint state), under applicable data protection or privacy restrictions (Mahaffey Fig. 13, [0161-0163], [0310]), for telemetry data transmitted by an endpoint device (Mahaffey [0213-0216]) whose endpoint agent is registered with a corresponding realm (Gupta [0051-0057] policies can be set based on endpoint group and compliance module provides for design/implementation/regulatory compliance to enforce the policies of the network; [0091] by looking at the endpoints the applicable policies can be retrieved), wherein each respective one of the endpoint devices is associated with a corresponding one of the realm definitions by virtue the endpoint device’s endpoint agent having registered with a realm having that realm definition (Gupta [0051-0057] policies can be set based on endpoint group and compliance module provides for design/implementation/regulatory compliance to enforce the policies of the network; [0091] by looking at the endpoints the applicable policies can be retrieved).
Regarding Claim 16:
Mahaffey discloses the computer network of claim 15 (Mahaffey Fig. 1 computer network 100, [0036]) … under the applicable data protection or privacy restrictions (Mahaffey [0310-0318] contextual information (such as location) used to determine presence or absence of security/privacy policies).
Mahaffey does not disclose a computer network wherein each respective one of the plurality of realm definitions further identifies one or more permissible routes through the network, … for the telemetry data transmitted by any of the endpoint devices having endpoint agents registered with a realm for that realm definition.
Gupta teaches a network wherein each respective one of the plurality of realm definitions further identifies one or more permissible routes through the network (Gupta [0040] specific route through the network is allowed or denied), … for the telemetry data transmitted by any of the endpoint devices having endpoint agents registered with a realm for that realm definition (Gupta [0051-0053] permissible routes, [0091] by looking at the endpoints the applicable policies can be retrieved).
It would have been obvious to one having ordinary skill in the art before the time the invention was effective filed to combine the network and awareness of privacy and security policies disclosed by Mahaffey with the endpoint agents and permissible routes as taught by Gupta.
The motivation for this combination would be to ensure that the collected telemetry data is not involved in network misconfigurations or vulnerabilities as discussed by Gupta [0053].
Regarding Claim 17:
Mahaffey discloses the computer network of claim 16 (Mahaffey Fig. 1 computer network 100, [0036]).
Mahaffey does not disclose wherein the transmission of the collected telemetry data by each respective endpoint agent is restricted to: being transmitted to a destination selected from one of the permissible destination data processing facilities identified in the realm definition of the realm with which the associated endpoint agent is registered, and being transmitted via a permissible one of the routes through the network identified in the realm definition of the realm with which the associated endpoint agent is registered.
Gupta teaches a network wherein the transmission of the collected telemetry data by each respective endpoint agent is restricted to: being transmitted to a destination selected from one of the permissible destination data processing facilities identified in the realm definition of the realm with which the associated endpoint agent is registered (Gupta [0050-0055] permissible routes and policy verification with conformance evaluation), and being transmitted via a permissible one of the routes through the network identified in the realm definition of the realm with which the associated endpoint agent is registered (Gupta [0050-0055], [0091]).
It would have been obvious to one having ordinary skill in the art before the time the invention was effective filed to combine the network disclosed by Mahaffey with the restriction of telemetry data transmission to permissible routes as taught by Gupta.
The motivation for this combination would be to ensure compliance by only allowing the transmission of user telemetry data through locations that match the policy of the source, and to improve the potential efficiency of policies as a whole as discussed by Gupta [0054].
Regarding Claim 19:
The combination of Mahaffey and Gupta further teaches the computer network of claim 2 (Mahaffey Fig. 1 computer network 100, [0036]), wherein the alert is made available on the computer network to a human system administrator (Mahaffey [0078] IT admin is alerted with anomalous activity).
Regarding Claim 20:
The combination of Mahaffey and Gupta further teaches the computer network of claim 2 (Mahaffey Fig. 1 computer network 100, [0036]), wherein each respective one of the computer-based endpoint agents is configured to collect and transmit one or more screenshots from the corresponding endpoint device where the user activity occurred to a cloud storage device for storage (Mahaffey [0222-0223] notification modules can generate and provide user notifications including images).
Regarding Claim 21:
The combination of Mahaffey and Gupta further teaches the computer network of claim 20 (Mahaffey Fig. 1 computer network 100, [0036]), wherein the alert made available on the computer network is accompanied by one or more of the screenshots from the corresponding endpoint device where the user activity occurred and that were transmitted to the cloud storage device for storage (Mahaffey [0222-0223], [0377] logging alert and device traffic for analysis and storage), along with associated with metadata from a triggering user activity (Mahaffey [0290-0292], [0377]).
Regarding Claim 22:
Mahaffey discloses the computer network of claim 1 (Mahaffey Fig. 1 computer network 100, [0036]).
Mahaffey does not disclose a computer network further comprising: a landlord service; an identify access management (IAM) service; a registry; an activity monitor; a cloud storage service; and a user interface at each respective one of the plurality of user endpoint devices.
Gupta teaches a computer network further comprising: a landlord service (Gupta [0069-0070] and Fig. 2 compliance module manages and defines policies and realms (end-point groups)); an identify access management (IAM) service (Gupta [0069] “The person or entity authentication requirement 356 assures that policies and procedures are in place to identify persons or entities seeking access to protected electronic information.”); a registry (Gupta [0069]); an activity monitor (Gupta [0084] network environment sensors 420 can capture data at a granular packet level); a cloud storage service (a cloud storage service;); and a user interface at each respective one of the plurality of user endpoint devices (Gupta Fig. 4, [0077] network environment employs interfaces, and [0096] any of the computing devices in the network can facilitate user interaction with a variety of interfaces).
It would have been obvious to one having ordinary skill in the art at before the time the invention was effective filed to combine the network disclosed by Mahaffey with the additional further elements taught by Gupta.
The motivation for this combination would be in order to better accomplish the goal of ensuring that the data in transmission is treating according the correct policy in various locations labelled as important by Mahaffey [0161-0163] and further accomplished with the additional elements incorporated by Gupta.
Regarding Claim 23:
Mahaffey discloses the computer network of claim 22 (Mahaffey Fig. 1 computer network 100, [0036]).
Mahaffey does not disclose a computer network wherein each of the user interfaces is configured to receive an administrator’s request to create a realm, and, in response to the administrator’s request, to send a UI request to the landlord service to create the realm, wherein the landlord service is configured to send a landlord request to the IAM service to create an agent realm role, in response to receiving the UI request, wherein the IAM service is configured to respond to the landlord request by creating an agent realm role, assigning an agent realm role principal identifier to the landlord service, and sending the agent realm role principal identifier to the landlord service, wherein the landlord service is configured to then sends a landlord-registry request to the registry to create a system configuration for the agent realm, and wherein the registry is configured to respond to the landlord-registry request by creating the system configuration for the agent realm and then sending a confirmation to the landlord service.
Gupta teaches a network wherein each of the user interfaces is configured to receive an administrator’s request to create a realm (Gupta Fig. 1 and [0020-0022] configuration manager 102 provisions and maintains the sensors within a network), and, in response to the administrator’s request, to send a UI request to the landlord service to create the realm (Gupta Fig. 1 and [0020-0022] configuration manager 102 handles creation), wherein the landlord service is configured to send a landlord request to the IAM service to create an agent realm role (Gupta Fig. 1 and [0020-0022] configuration manager 102 handles creation), in response to receiving the UI request, wherein the IAM service is configured to respond to the landlord request by creating an agent realm role (Gupta Fig. 1 and [0050-0051] traffic monitoring system can detect changes to topology and be configured by a network administrator (the agent realm role)), assigning an agent realm role principal identifier to the landlord service (Gupta Fig. 1 and [0021] configuration manager can assign individual identifiers), and sending the agent realm role principal identifier to the landlord service (Gupta Fig. 1 and [0021] configuration manager keeps identifiers stored and apply updates), wherein the landlord service is configured to then send a landlord-registry request to the registry to create a system configuration for the agent realm (Gupta Fig. 1 and [0020-0022] configuration manager 102 handles configuration and updates to settings), and wherein the registry is configured to respond to the landlord-registry request by creating the system configuration for the agent realm (Gupta Fig. 1 and [0020-0022] configuration manager 102 handles configuration and updates to settings) and then sending a confirmation to the landlord service (Gupta [0021] “configuration manager 102 may request for status updates and/or receive heartbeat messages, initiate performance tests, generate health checks, and perform other health monitoring tasks“).
It would have been obvious to one having ordinary skill in the art at before the time the invention was effective filed to combine the network disclosed by Mahaffey with the additional agent realm roles as taught by Gupta.
The motivation for this combination would be to ensure the efficiency and longevity of the entire system because the configuration manager taught by Gupta is more than capable of creating the realm’s sensors, performing updates, and health checks.
Regarding Claim 24:
The combination of Mahaffey and Gupta further discloses the computer network of claim 23 (Mahaffey Fig. 1 computer network 100, [0036]), wherein information relating to the system configuration created by the registry is stored in memory at a data processing facility accessible within the associated realm (Gupta [0029-0031]; [0036] data lake 130 stores a repository of attributes).
Regarding Claim 25:
The combination of Mahaffey and Gupta further discloses the computer network of claim 23 (Mahaffey Fig. 1 computer network 100, [0036]), wherein the UI request includes setup information comprising default data retention information, default routing information as well as agent configuration settings (Gupta Fig. 1 and [0020-0022] configuration manager 102 handles creation; [0048] web-front end and database defaults; [0040] routing information contained in policy attributes 138).
Regarding Claim 26:
The combination of Mahaffey and Gupta further discloses the computer network of claim 1 (Mahaffey Fig. 1 computer network 100, [0036]), wherein collecting the telemetry data that is related to the user activity comprises collecting metadata about the user activity (Mahaffey [0213-0216], [0290-0292], [0377]).
Regarding Claim 27:
The combination of Mahaffey and Gupta further discloses the computer network of claim 26 (Mahaffey Fig. 1 computer network 100, [0036]), wherein each endpoint agent is configured to collect and transmit one or more screenshots of a triggering user activity to a cloud storage service (Mahaffey [0222-0223], [0377] logging alert and device traffic for analysis and storage), and wherein the metadata is processed to determine whether the user activity represented by the metadata might pose a threat to an enterprise (Mahaffey [0213] “malware identifier 666 may be configured to identify attempts to exploit vulnerabilities of computing device 601 and applications 604 which may be installed and running on computing device 601. Malware identifier 666 may monitor traffic and identify malicious files and/or activities based on a predetermined list of filenames. Malware identifier 666 may also identify malicious files and/or activities based on detected behaviors”); the method further comprising: sending an alert to the system administrator, wherein the alert is accompanied by the one or more of the screenshots that were stored in the cloud storage and that are associated with the metadata from the triggering user activity (Mahaffey [0222-0223], [0377] logging alert and device traffic for analysis and storage).
Regarding Claim 28:
The combination of Mahaffey and Gupta further discloses the computer network of claim 26 (Mahaffey Fig. 1 computer network 100, [0036]), wherein each data processing facility is configured to: analyze the metadata to identify potential insider threats posed by the user activity associated with the telemetry data; and create the alert if any such insider threat is identified, wherein the insider threat is an exfiltration risk (Mahaffey [0213] “malware identifier 666 may be configured to identify attempts to exploit vulnerabilities of computing device 601 and applications 604 which may be installed and running on computing device 601. Malware identifier 666 may monitor traffic and identify malicious files and/or activities based on a predetermined list of filenames. Malware identifier 666 may also identify malicious files and/or activities based on detected behaviors”, [0377] in response an alert may be sent (“e.g., via email, to a security alerting console, to a SIEM system”) amongst other actions taken).
Regarding Claim 29:
The combination of Mahaffey and Gupta further discloses the computer network of claim 22(Mahaffey Fig. 1 computer network 100, [0036]), wherein each of the endpoint agents periodically sends a heartbeat to the registry (Gupta Fig. 1 and [0020-0022] configuration manager 102 handles configuration and updates to settings and “configuration manager 102 may request for status updates and/or receive heartbeat messages, initiate performance tests, generate health checks, and perform other health monitoring tasks”), and wherein the registry responds with a confirmation receipt and any configuration updates that are relevant to that endpoint agent (Gupta Fig. 1 and [0020-0022] configuration manager 102 handles configuration and updates to settings and “configuration manager 102 may request for status updates and/or receive heartbeat messages, initiate performance tests, generate health checks, and perform other health monitoring tasks”, [0069]).
Conclusion
The prior art made of record in the submitted PTO-892 Notice of References Cited and not relied upon is considered pertinent to applicant’s disclosure.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MIGUEL A LOPEZ whose telephone number is (703)756-1241. The examiner can normally be reached 8:00AM-5:00PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jorge Ortiz-Criado can be reached on 5712727624. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/M.A.L./ Examiner, Art Unit 2496
/JORGE L ORTIZ CRIADO/Supervisory Patent Examiner, Art Unit 2496