Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 03/11/2026 has been entered.
Response to Amendments / Arguments
Regarding the rejection(s) of claims under 35 USC 103:
Applicant’s arguments, filed 03/11/2026, in view of the amended claims, have been fully considered and are persuasive. Therefore the rejection is withdrawn, however the rejection is further upheld in view of Agarwwal et al. (US 20220210162 A1).
It is also noted that the amendments raise 112(a) lacking written description issues. These issues are addressed in the rejection below.
DETAILED ACTION
This is a reply to the arguments filed on 03/11/2026, in which, claims 1-2, 4-10, 12-21 and 23 are pending. Claims 1, 9, and 17 are independent. Claims 3, 11 and 22 are canceled.
When making claim amendments, the applicant is encouraged to consider the references in their entireties, including those portions that have not been cited by the examiner and their equivalents as they may most broadly and appropriately apply to any particular anticipated claim amendments.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 1-2, 4-10, 12-21 and 23 rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention.
Regarding claims 1, 9 and 17 limitation "determining, based on the context data, that the threat behavior indicates a lateral movement from the endpoint device through the private cloud to the asset in the public cloud using a second user identity of the plurality of second user identities." This limitation requires that the determined behavior indicates lateral movement that follows a specific traversal path. Namely, from the endpoint device, through a private cloud, and terminating at an asset residing in a public cloud. The specification fails to provide adequate written description support for this specific lateral movement topology.
While the specification generally describes lateral movement as a threat behavior ([0011], [0053]) and references both public and private clouds as environments in which the security appliance may be deployed ([0010], [0029]), the specification does not describe, in any embodiment or figure, a lateral movement path that traverses from an endpoint device through a private cloud to a public cloud asset as a discrete, identifiable sequence, let alone determining behavior indicating such a path. FIG. 1, which illustrates the primary network scenario of the invention, depicts endpoint devices connecting generically to network(s)/cloud(s) 120 without describing or illustrating a traversal path that specifically routes through a private cloud as an intermediate before reaching a public cloud asset.
Accordingly, claim 1 lacks adequate written description support for the limitations recited. Any claims depending on claim 1 are rejected on similar grounds to the extent they incorporate these limitations.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-2, 9-10, 17-18, 21 and 23 are rejected under 35 U.S.C. 103 as being unpatentable over Kumar et al. (US 20210314337 A1, referred to as Kumar) in view of Stokes et al. (US 20180367548 A1, referred to as Stokes), in view of Agarwwal et al. (US 20220210162 A1, referred to as Agarwwal).
In reference to claim 1, A method implemented on a security appliance for identity control, the method comprising: receiving, from an endpoint device, telemetry data (Kumar: [0036]-[0039], [0050]-[0054] and [0099]-[0101] Provides for receiving event data (telemetry) from endpoint devices through endpoint applications.)
Determining, based on the telemetry data, a threat behavior associated with a first user identity (Kumar: [0037] and [0095]-[0096] Provides for determining threat behaviors (suspicious downloads, privilege elevation) associated with specific user identities based on event data (telemetry).)
Determining, based at least in part of the first user identity and by querying an identity database, a plurality of second user identities associated with the first user identity (Kumar: [0029], [0037], [0053] and [0096] Provides for querying Active Directory (an identity database that authenticates and authorizes all users) to track privilege elevations where a first user identity elevates to administrative accounts (second user identities) associated with the first user identity.)
Determining a plurality of computing domains associated with the plurality of second user identities (Kumar: [0029], [0053], [0083] and [0091] Provides for determining AD domains and device groups (computing domains) associated with user identities, including tracking user access to multiple device groups (N1 and N2) and paths to domain controller servers.)
Determining context data associated with the threat behavior (Kumar: [0040] and [0056]-[0059] Provides for determining classification metadata and feature vectors that provide context about threat behaviors.)
Determining , based on the context data, that the threat behavior indicates a lateral movement from the endpoint device through the private computing domain to the asset in the public computing domain using a second user identity of the plurality of second user identities (Kumar: [0029]-[0037] and [0086] Provides for determining lateral movement with privilege escalation from endpoints through multiple entities.)
Wherein at least one second user identity of the plurality of second user identities is escalated to a privileged level from the first user identity (Kumar: [0037], [0096] and [0110] Provides for privilege escalation where a user identity is elevated to higher privilege levels (e.g., administrative accounts).)
Kumar does not explicitly teach implementing a security action on the plurality of second user identities to prevent the lateral movement with privilege escalation from the endpoint device to attack the plurality of computing domains. However, Stokes discloses:
Implementing a security action on the second user identity to prevent the lateral movement with privilege escalation from the endpoint device to attack the asset in the public cloud (Stokes: [0043]-[0049] Provides for implementing security actions (automatically disabling user accounts or computers) to prevent lateral movement.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Kumar, which provides a method for detecting lateral movement and privilege escalation threats based on telemetry and context data, with the teachings of Stokes, which introduces implementing security actions to prevent lateral movement by disabling compromised identities. One of ordinary skill in the art would recognize the ability to incorporate Stokes's proactive security measures into Kumar's threat detection system to complete the security control loop. One of ordinary skill in the art would be motivated to make this modification in order to move from merely detecting threats to actively preventing them and contain security breaches more effectively by immediately disabling compromised identities.
Kumar in view of Stokes does not explicitly teach the endpoint device connecting to a private cloud, at least one computer domain of the plurality of computing domains corresponding to an asset in a public cloud, wherein the computing domain is a cloud
the endpoint device connecting to a private cloud, at least one computer domain of the plurality of computing domains corresponding to an asset in a public cloud and wherein the computing domain is a cloud (Agarwwal: [0002]-[0003] and [0067]-[0076] Provides for assets in a cloud environment (S3, SageMaker) accessible through escalated identities.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Kumar in view of Stokes, which together provide a method for detecting and preventing lateral movement threats through identity-based security controls, with the teachings of Agarwal, which introduces cloud computing environments including both private cloud endpoint connectivity and public cloud assets accessible through escalated identities. One of ordinary skill in the art would recognize the ability to extend the combined threat detection and prevention system to cloud computing architectures. One of ordinary skill in the art would be motivated to make this modification in order to address the growing security challenges in hybrid and multi-cloud environments where lateral movement increasingly targets cloud-based assets
In reference to claim 2, The method of claim 1, further comprising: implementing the security action on the first user identity to prevent attacks to the plurality of computing domains using the first user identity (Stokes: [0043]-[0049] Provides for disabling compromised accounts in general, which would include the initially compromised identity.)
In reference to claim 9, A system comprising: a processor, and a memory storing instructions executed by the processor to perform operations including: receiving, from an endpoint device, telemetry data (Kumar: [0036]-[0039], [0050]-[0054] and [0099]-[0101] Provides for receiving event data (telemetry) from endpoint devices through endpoint applications.)
Determining, based on the telemetry data, a threat behavior associated with a first user identity (Kumar: [0037] and [0095]-[0096] Provides for determining threat behaviors (suspicious downloads, privilege elevation) associated with specific user identities based on event data (telemetry).)
Determining, based at least in part of the first user identity and by querying an identity database, a plurality of second user identities associated with the first user identity (Kumar: [0029], [0037], [0053] and [0096] Provides for querying Active Directory (an identity database that authenticates and authorizes all users) to track privilege elevations where a first user identity elevates to administrative accounts (second user identities) associated with the first user identity.)
Determining a plurality of computing domains associated with the plurality of second user identities (Kumar: [0029], [0053], [0083] and [0091] Provides for determining AD domains and device groups (computing domains) associated with user identities, including track
Determining context data associated with the threat behavior (Kumar: [0040] and [0056]-[0059] Provides for determining classification metadata and feature vectors that provide context about threat behaviors.)
Determining , based on the context data, that the threat behavior indicates a lateral movement from the endpoint device through the private computing domain to the asset in the public computing domain using a second user identity of the plurality of second user identities (Kumar: [0029]-[0037] and [0086] Provides for determining lateral movement with privilege escalation from endpoints through multiple entities.)
Wherein at least one second user identity of the plurality of second user identities is escalated to a privileged level from the first user identity (Kumar: [0037], [0096] and [0110] Provides for privilege escalation where a user identity is elevated to higher privilege levels (e.g., administrative accounts).)
Kumar does not explicitly teach implementing a security action on the plurality of second user identities to prevent the lateral movement with privilege escalation from the endpoint device to attack the plurality of computing domains. However, Stokes discloses:
Implementing a security action on the second user identity to prevent the lateral movement with privilege escalation from the endpoint device to attack the asset in the public cloud (Stokes: [0043]-[0049] Provides for implementing security actions (automatically disabling user accounts or computers) to prevent lateral movement.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Kumar, which provides a method for detecting lateral movement and privilege escalation threats based on telemetry and context data, with the teachings of Stokes, which introduces implementing security actions to prevent lateral movement by disabling compromised identities. One of ordinary skill in the art would recognize the ability to incorporate Stokes's proactive security measures into Kumar's threat detection system to complete the security control loop. One of ordinary skill in the art would be motivated to make this modification in order to move from merely detecting threats to actively preventing them and contain security breaches more effectively by immediately disabling compromised identities.
Kumar in view of Stokes does not explicitly teach the endpoint device connecting to a private cloud, at least one computer domain of the plurality of computing domains corresponding to an asset in a public cloud, wherein the computing domain is a cloud
the endpoint device connecting to a private cloud, at least one computer domain of the plurality of computing domains corresponding to an asset in a public cloud and wherein the computing domain is a cloud (Agarwwal: [0002]-[0003] and [0067]-[0076] Provides for assets in a cloud environment (S3, SageMaker) accessible through escalated identities.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Kumar in view of Stokes, which together provide a method for detecting and preventing lateral movement threats through identity-based security controls, with the teachings of Agarwal, which introduces cloud computing environments including both private cloud endpoint connectivity and public cloud assets accessible through escalated identities. One of ordinary skill in the art would recognize the ability to extend the combined threat detection and prevention system to cloud computing architectures. One of ordinary skill in the art would be motivated to make this modification in order to address the growing security challenges in hybrid and multi-cloud environments where lateral movement increasingly targets cloud-based assets
In reference to claim 10, The system of claim 9, wherein the operations further comprise: implementing the security action on the first user identity to prevent attacks to the plurality of computing domains using the first user identity (Stokes: [0043]-[0049] Provides for disabling compromised accounts in general, which would include the initially compromised identity.)
In reference to claim 17, A computer-readable storage medium storing computer- readable instructions, that when executed by a processor, cause the processor to perform actions comprising: receiving, from an endpoint device, telemetry data (Kumar: [0036]-[0039], [0050]-[0054] and [0099]-[0101] Provides for receiving event data (telemetry) from endpoint devices through endpoint applications.)
Determining, based on the telemetry data, a threat behavior associated with a first user identity (Kumar: [0037] and [0095]-[0096] Provides for determining threat behaviors (suspicious downloads, privilege elevation) associated with specific user identities based on event data (telemetry).)
Determining, based at least in part of the first user identity and by querying an identity database, a plurality of second user identities associated with the first user identity (Kumar: [0029], [0037], [0053] and [0096] Provides for querying Active Directory (an identity database that authenticates and authorizes all users) to track privilege elevations where a first user identity elevates to administrative accounts (second user identities) associated with the first user identity.)
Determining a plurality of computing domains associated with the plurality of second user identities (Kumar: [0029], [0053], [0083] and [0091] Provides for determining AD domains and device groups (computing domains) associated with user identities, including track
Determining context data associated with the threat behavior (Kumar: [0040] and [0056]-[0059] Provides for determining classification metadata and feature vectors that provide context about threat behaviors.)
Determining, based at least in part on the context data, information associated with the endpoint device, wherein the information associated with the endpoint device includes at least one of an IP address of the endpoint device, a type of the endpoint device, users registered to the endpoint device, or geographic location of the endpoint device (Kumar: [0059] and [0088] Provides for determining endpoint device contextual information including device type and IP address from classification metadata.)
Determining , based on the context data, that the threat behavior indicates a lateral movement from the endpoint device through the private computing domain to the asset in the public computing domain using a second user identity of the plurality of second user identities (Kumar: [0029]-[0037] and [0086] Provides for determining lateral movement with privilege escalation from endpoints through multiple entities.)
Wherein at least one second user identity of the plurality of second user identities is escalated to a privileged level from the first user identity (Kumar: [0037], [0096] and [0110] Provides for privilege escalation where a user identity is elevated to higher privilege levels (e.g., administrative accounts).)
Kumar does not explicitly teach implementing a security action on the plurality of second user identities to prevent the lateral movement with privilege escalation from the endpoint device to attack the plurality of computing domains. However, Stokes discloses:
Determining, based at leat in part on the information associated with the endpoint device, the threat behavior, and a category of the computer domain under attack being the asset in the public cloud, a security action (Stokes: [0043] Provides for determining a security action based on combined factors including detection type and a configurable threshold.)
Implementing a security action on the second user identity to prevent the lateral movement with privilege escalation from the endpoint device to attack the asset in the public cloud (Stokes: [0043]-[0049] Provides for implementing security actions (automatically disabling user accounts or computers) to prevent lateral movement.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Kumar, which provides a method for detecting lateral movement and privilege escalation threats based on telemetry and context data, with the teachings of Stokes, which introduces implementing security actions to prevent lateral movement by disabling compromised identities. One of ordinary skill in the art would recognize the ability to incorporate Stokes's proactive security measures into Kumar's threat detection system to complete the security control loop. One of ordinary skill in the art would be motivated to make this modification in order to move from merely detecting threats to actively preventing them and contain security breaches more effectively by immediately disabling compromised identities.
Kumar in view of Stokes does not explicitly teach the endpoint device connecting to a private cloud, at least one computer domain of the plurality of computing domains corresponding to an asset in a public cloud, wherein the computing domain is a cloud
the endpoint device connecting to a private cloud, at least one computer domain of the plurality of computing domains corresponding to an asset in a public cloud and wherein the computing domain is a cloud (Agarwwal: [0002]-[0003] and [0067]-[0076] Provides for assets in a cloud environment (S3, SageMaker) accessible through escalated identities.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Kumar in view of Stokes, which together provide a method for detecting and preventing lateral movement threats through identity-based security controls, with the teachings of Agarwal, which introduces cloud computing environments including both private cloud endpoint connectivity and public cloud assets accessible through escalated identities. One of ordinary skill in the art would recognize the ability to extend the combined threat detection and prevention system to cloud computing architectures. One of ordinary skill in the art would be motivated to make this modification in order to address the growing security challenges in hybrid and multi-cloud environments where lateral movement increasingly targets cloud-based assets
In reference to claim 18, The computer-readable storage medium of claim 17, wherein the actions further comprise: implementing the security action on the first user identity to prevent attacks to the plurality of computing domains using the first user identity (Stokes: [0043]-[0049] Provides for disabling compromised accounts in general, which would include the initially compromised identity.)
In reference to claim 21, The method of claim 1, further comprising: determining, based at least in part on the context data, informatio associated with the endpoint device; determining categories associated with the plurality of computing domains; and determining the security action based at least in part on information associated with the endpoint device, the threat behavior, or the categories associated with the plurality of computing domains (Kumar: [0059], [0118], [0089] and [0132]-[0134] Provides for categorize devices (workstations, servers, critical resources) and use these categories along with endpoint information and threat behaviors to determine appropriate actions.)
In reference to claim 23, the method of claim 21, wherein the information associated with the endpoint device includes at least one of an IP address of the endpoint device, a type of the endpoint device, users registered to the endpoint device, or geographic location of the endpoint device (Kumar: [0059], [0088] and [0101] Provides for classification metadata associated with endpoint devices including device type (workstation, server, printer, tablet, smartphone, endpoint device), users that interact with devices, and IP address information associated with network activities.)
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 4, 6-8, 12, 14-16, and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Kumar et al. (US 20210314337 A1, referred to as Kumar) in view of Stokes et al. (US 20180367548 A1, referred to as Stokes), in view of Agarwwal et al. (US 20220210162 A1, referred to as Agarwwal) Thomas et al. (WO 2022087510 A1, referred to as Thomas).
In reference to claim 4, Kumar in view of Stokes discloses the method of claim 1 However they do not explicitly disclose blocking authentication to the plurality of computing domains in the context of a ransomware threat. However, Thomas teaches:
Wherein the context data indicates that the threat behavior is related to a ransomware actor intending to laterally move from the endpoint device to the asset in the public cloud and the method further includes: basd on the threat behavior being related to the ransomware actor determining the security action to include: blocking of the second user identity to access the asset in the public cloud from the endpoint device through the private cloud, (Thomas: [00159] provides for applying enterprise policies to control file access and movement. Paragraph [00178] further provides for applying enterprise policies based on the trustworthiness of a file, where changes suggesting ransomware result in remedial measures.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Kumar in view of Stokes, which provides a method for detecting and mitigating lateral movement threats, with the teachings of Thomas, which introduces blocking authentication to prevent ransomware-related lateral movement. One of ordinary skill in the art would recognize the ability to incorporate Thomas's ransomware-specific authentication blocking into the combined system to address the specific threat of ransomware propagation. One of ordinary skill in the art would be motivated to make this modification in order to provide specialized protection against ransomware attacks
In reference to claim 6, Kumar in view of Stokes discloses the method of claim 1, however they do not explicitly disclose the specific detection of threat behavior related to keyboard activity, particularly concerning access attempts using remote desktop protocol (RDP) or the implementation of multi-factor authentication (MFA) in response. However, Thomas teaches:
Wherein the context data indicates that the threat behavior is related to a keyboard activity on the endpoint device, and the method further comprises: determining, based on the keyboard activity, an attempt to access a computing domain of the plurality of computing domains using a remote desktop protocol, (Thomas: [00316] provides for using user confirmation on a second endpoint device to control Remote Desktop Protocol (RDP) session connections.)
Implementing multi-factor authentication (MFA) on a corresponding second user identity to access the computing domain from the endpoint device, (Thomas: [00283] provides for enhanced two-factor authentication where an attempted authentication on a first endpoint triggers a request for a second authentication on a second endpoint associated with the user.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Kumar in view of Stokes, which provides a method for detecting and mitigating lateral movement threats, with the teachings of Thomas, which introduces monitoring keyboard activity to detect RDP access attempts and implementing multi-factor authentication as a security response. One of ordinary skill in the art would recognize the ability to incorporate Thomas's RDP-focused security controls and MFA implementation into the combined system to enhance protection against remote access threats. One of ordinary skill in the art would be motivated to make this modification in order to specifically address the common attack vector of RDP-based lateral movement.
In reference to claim 7, Kumar in view of Stokes discloses the method of claim 1, however they do not explicitly disclose the security appliance being communicatively connected to various cloud environments such as a public cloud, private cloud, or hybrid cloud. However, Thomas teaches:
Wherein the security appliance is communicatively connected to at least one of the public cloud, the private cloud, or a hybrid cloud, (Thomas: [0061] provides for extending threat protection beyond the network boundaries of the enterprise facility to include clients in a cloud computing instances.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Kumar in view of Stokes, which provides a method for detecting and mitigating lateral movement threats, with the teachings of Thomas, which introduces extending threat protection to cloud computing environments. One of ordinary skill in the art would recognize the ability to expand the security appliance's connectivity to include cloud environments within the existing threat detection and mitigation framework. One of ordinary skill in the art would be motivated to make this modification in order to address the modern reality of distributed computing infrastructures.
In reference to claim 8, Wherein the security appliance is communicatively connected to the public cloud, and the assets in the public cloud includes at least one of storage bucket on the public cloud, Git, source code repositories, or application servers, (Thomas: [0062] provides for communication with cloud applications and services. Paragraph [0091] further provides for a cloud enterprise facility including servers and a firewall, which could be related to managing assets such as source code repositories and application servers in the public cloud.)
In reference to claim 12, Kumar in view of Stokes discloses the system of claim 9 however, they do not explicitly disclose blocking authentication to the plurality of computing domains in the context of a ransomware threat. However, Thomas teaches:
Wherein the context data indicates that the threat behavior is related to a ransomware actor intending to laterally move from the endpoint device to the asset in the public cloud and the method further includes: basd on the threat behavior being related to the ransomware actor determining the security action to include: blocking of the second user identity to access the asset in the public cloud from the endpoint device through the private cloud, (Thomas: [00159] provides for applying enterprise policies to control file access and movement. Paragraph [00178] further provides for applying enterprise policies based on the trustworthiness of a file, where changes suggesting ransomware result in remedial measures.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Kumar in view of Stokes, which provides a method for detecting and mitigating lateral movement threats, with the teachings of Thomas, which introduces blocking authentication to prevent ransomware-related lateral movement. One of ordinary skill in the art would recognize the ability to incorporate Thomas's ransomware-specific authentication blocking into the combined system to address the specific threat of ransomware propagation. One of ordinary skill in the art would be motivated to make this modification in order to provide specialized protection against ransomware attacks.
In reference to claim 14, Kumar in view of Stokes discloses the system of claim 9 however, they do not explicitly disclose the specific detection of threat behavior related to keyboard activity, particularly concerning access attempts using remote desktop protocol (RDP) or the implementation of multi-factor authentication (MFA) in response. However, Thomas teaches:
Wherein the context data indicates that the threat behavior is related to a keyboard activity on the endpoint device, and the method further comprises: determining, based on the keyboard activity, an attempt to access a computing domain of the plurality of computing domains using a remote desktop protocol, (Thomas: [00316] provides for using user confirmation on a second endpoint device to control Remote Desktop Protocol (RDP) session connections.) Implementing multi-factor authentication (MFA) on a corresponding second user identity to access the computing domain from the endpoint device, (Thomas: [00283] provides for enhanced two-factor authentication where an attempted authentication on a first endpoint triggers a request for a second authentication on a second endpoint associated with the user.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Kumar in view of Stokes, which provides a method for detecting and mitigating lateral movement threats, with the teachings of Thomas, which introduces monitoring keyboard activity to detect RDP access attempts and implementing multi-factor authentication as a security response. One of ordinary skill in the art would recognize the ability to incorporate Thomas's RDP-focused security controls and MFA implementation into the combined system to enhance protection against remote access threats. One of ordinary skill in the art would be motivated to make this modification in order to specifically address the common attack vector of RDP-based lateral movement.
In reference to claim 15, Kumar in view of Stokes discloses the system of claim 9 however, they do not explicitly disclose the security appliance being communicatively connected to various cloud environments such as a public cloud, private cloud, or hybrid cloud. However, Thomas teaches:
Wherein the security appliance is communicatively connected to at least one of the public cloud, tbe private cloud, or a hybrid cloud, (Thomas: [0061] provides for extending threat protection beyond the network boundaries of the enterprise facility to include clients in a cloud computing instances.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Kumar in view of Stokes, which provides a method for detecting and mitigating lateral movement threats, with the teachings of Thomas, which introduces extending threat protection to cloud computing environments. One of ordinary skill in the art would recognize the ability to expand the security appliance's connectivity to include cloud environments within the existing threat detection and mitigation framework. One of ordinary skill in the art would be motivated to make this modification in order to address the modern reality of distributed computing infrastructures.
In reference to claim 16, Wherein the security appliance is communicatively connected to the public cloud, and the plurality of computing domains are public domain assets including at least one of storage bucket on the public cloud, Git, source code repositories, or application servers, (Thomas: [0062] provides for communication with cloud applications and services. Paragraph [0091] further provides for a cloud enterprise facility including servers and a firewall, which could be related to managing assets such as source code repositories and application servers in the public cloud.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Petersen, which involve a security appliance connected to various cloud environments, with the teachings of Thomas, which detail communication with cloud applications and management of cloud enterprise facilities. One of ordinary skill in the art would recognize the ability to adapt these teachings to specifically connect a security appliance to the public cloud for managing a range of public domain assets. One of ordinary skill in the art would be motivated to make this modification in order to enhance security management and integration across diverse cloud-based assets and services.
In reference to claim 20, Kumar in view of Stokes discloses the computer-readable storage medium of claim 17 however, they do not explicitly disclose the security appliance being specifically connected to a public cloud and managing public domain assets including storage buckets, Git, source code repositories, or application servers. However, Thomas teaches:
Wherein the security appliance is communicatively connected to the public cloud, and the asset in the public cloud includes at least one of storage bucket on the public cloud, Git, source code repositories, or application servers, (Thomas: [0062] provides for communication with cloud applications and services. Paragraph [0091] further provides for a cloud enterprise facility including servers and a firewall, which could be related to managing assets such as source code repositories and application servers in the public cloud.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Petersen, which involve a security appliance connected to various cloud environments, with the teachings of Thomas, which detail communication with cloud applications and management of cloud enterprise facilities. One of ordinary skill in the art would recognize the ability to adapt these teachings to specifically connect a security appliance to the public cloud for managing a range of public domain assets. One of ordinary skill in the art would be motivated to make this modification in order to enhance security management and integration across diverse cloud-based assets and services.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 5, 13 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Kumar et al. (US 20210314337 A1, referred to as Kumar) in view of Stokes et al. (US 20180367548 A1, referred to as Stokes), in view of Thomas et al. (WO 2022087510 A1, referred to as Thomas), in further view of Aziz (US 8528086 B1, referred to as Aziz).
In reference to claim 5, Kumar in view of Stokes discloses the method of claim 1 however, they do not explicitly disclose implementing multi-factor authentication (MFA) or blocking authentication to computing domains based on the plurality of second user identities, nor the specific detection of a worm's lateral movement and corresponding security actions. However, Thomas teaches:
based on the threat behavior being indicating the lateral movement, determining The security action further includes at least one of: Implementing multi-factor authentication (MFA) on second user identity to access the asset in the public cloud from the endpoint device through the private cloud, or blocking authentication of the second user identity to access the asset in the public cloud from the endpoint device through the private cloud, (Thomas: [00283] provides for enhanced MFA processes that can be added to applications.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Kumar in view of Stokes, which provides a method for detecting and mitigating lateral movement threats, with the teachings of Thomas, which introduces implementing multi-factor authentication and blocking authentication as security responses. One of ordinary skill in the art would recognize the ability to incorporate Thomas's authentication-based security measures into the combined system to provide additional layers of protection. One of ordinary skill in the art would be motivated to make this modification in order to strengthen security controls by requiring additional authentication factors for access.
Kumar in view of Stokes in view of Thomas does not explicitly disclose the detection and response to lateral movement of a worm, however, Aziz teaches:
Wherein the context data indicates that the threat behavior is a lateral movement of a worm, (Aziz: Col. 3 Line 65 – Col. 4 Line 10, provides for a method for detecting a worm’s lateral movement and determining a response based on the detected behavior.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Kumar in view of Stokes and Thomas, which together provide a method for detecting lateral movement threats and implementing authentication-based security measures, with the teachings of Aziz, which introduces specific detection and response capabilities for worm lateral movement. One of ordinary skill in the art would recognize the ability to incorporate Aziz's worm-specific detection into the combined system to address this particular category of malware threats. One of ordinary skill in the art would be motivated to make this modification in order to provide specialized threat detection for worms.
In reference to claim 13, Kumar in view of Stokes discloses the system of claim 9 however, they do not explicitly disclose implementing multi-factor authentication (MFA) or blocking authentication to computing domains based on the plurality of second user identities, nor the specific detection of a worm's lateral movement and corresponding security actions. However, Thomas teaches:
based on the threat behavior being indicating the lateral movement, determining The security action further includes at least one of: Implementing multi-factor authentication (MFA) on second user identity to access the asset in the public cloud from the endpoint device through the private cloud, or blocking authentication of the second user identity to access the asset in the public cloud from the endpoint device through the private cloud, (Thomas: [00283] provides for enhanced MFA processes that can be added to applications.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Kumar in view of Stokes, which provides a method for detecting and mitigating lateral movement threats, with the teachings of Thomas, which introduces implementing multi-factor authentication and blocking authentication as security responses. One of ordinary skill in the art would recognize the ability to incorporate Thomas's authentication-based security measures into the combined system to provide additional layers of protection. One of ordinary skill in the art would be motivated to make this modification in order to strengthen security controls by requiring additional authentication factors for access.
Kumar in view of Stokes in view of Thomas does not explicitly disclose the detection and response to lateral movement of a worm, however, Aziz teaches:
Wherein the context data indicates that the threat behavior is a lateral movement of a worm, (Aziz: Col. 3 Line 65 – Col. 4 Line 10, provides for a method for detecting a worm’s lateral movement and determining a response based on the detected behavior.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Kumar in view of Stokes and Thomas, which together provide a method for detecting lateral movement threats and implementing authentication-based security measures, with the teachings of Aziz, which introduces specific detection and response capabilities for worm lateral movement. One of ordinary skill in the art would recognize the ability to incorporate Aziz's worm-specific detection into the combined system to address this particular category of malware threats. One of ordinary skill in the art would be motivated to make this modification in order to provide specialized threat detection for worms.
In reference to claim 19, Kumar in view of Stokes discloses the computer-readable storage medium of claim 17 however, they do not explicitly disclose implementing multi-factor authentication (MFA) or blocking authentication to computing domains based on the plurality of second user identities, However, Thomas teaches:
Tbased on the threat behavior being indicating the lateral movement, determining The security action further includes at least one of: Implementing multi-factor authentication (MFA) on second user identity to access the asset in the public cloud from the endpoint device through the private cloud, or blocking authentication of the second user identity to access the asset in the public cloud from the endpoint device through the private cloud, (Thomas: [00283] provides enhanced MFA processes that can be added to applications, relevant to implementing MFA using the plurality of second user identities.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Kumar in view of Stokes, which provides a method for detecting and mitigating lateral movement threats, with the teachings of Thomas, which introduces monitoring keyboard activity to detect RDP access attempts and implementing multi-factor authentication as a security response. One of ordinary skill in the art would recognize the ability to incorporate Thomas's RDP-focused security controls and MFA implementation into the combined system to enhance protection against remote access threats. One of ordinary skill in the art would be motivated to make this modification in order to specifically address the common attack vector of RDP-based lateral movement.
Kumar in view of Stokes in view of Thomas does not explicitly disclose the detection and response to lateral movement of a worm, however, Aziz teaches:
Wherein the context data indicates that the threat behavior is a lateral movement of a worm, (Aziz: Col. 3 Line 65 – Col. 4 Line 10, provides for a method for detecting a worm’s lateral movement and determining a response based on the detected behavior.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Kumar in view of Stokes and Thomas, which together provide a method for detecting lateral movement threats and implementing authentication-based security measures, with the teachings of Aziz, which introduces specific detection and response capabilities for worm lateral movement. One of ordinary skill in the art would recognize the ability to incorporate Aziz's worm-specific detection into the combined system to address this particular category of malware threats. One of ordinary skill in the art would be motivated to make this modification in order to provide specialized threat detection for worms.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See PTO-892.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to AIDAN EDWARD SHAUGHNESSY whose telephone number is (703)756-1423. The examiner can normally be reached on Monday-Friday from 7:30am to 5pm.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Nickerson, can be reached at telephone number (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from Patent Center and the Private Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from Patent Center or Private PAIR. Status information for unpublished applications is available through Patent Center and Private PAIR for authorized users only. Should you have questions about access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) Form at https://www.uspto.gov/patents/usptoautomated-interview-request-air-form.
/A.E.S./Examiner, Art Unit 2432
/Jeffrey Nickerson/Supervisory Patent Examiner, Art Unit 2432