Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This action is in response to the communication filed on 4/13/26.
Claims 1 – 3, 5 – 10, 12 – 17, and 19 – 21 are pending.
All objections and rejections not set forth below have been withdrawn.
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 4/13/26 has been entered.
Drawings
The drawings are objected to under 37 CFR 1.83(a). The drawings must show every feature of the invention specified in the claims. Therefore, the features of “… maintain a Bayesian network for a user … each threat detector configured to detect a respective condition in network traffic and generate a corresponding signal mapped to a corresponding node…” must be shown or the feature(s) canceled from the claim(s). No new matter should be entered.
Corrected drawing sheets in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. The figure or figure number of an amended drawing should not be labeled as “amended.” If a drawing figure is to be canceled, the appropriate figure must be removed from the replacement sheet, and where necessary, the remaining figures must be renumbered and appropriate changes made to the brief description of the several views of the drawings for consistency. Additional replacement sheets may be necessary to show the renumbering of the remaining figures. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance.
Specification
The specification is objected to as failing to provide proper antecedent basis for the claimed subject matter. See 37 CFR 1.75(d)(1) and MPEP § 608.01(o). Correction of the following is required:
The applicant’s original disclosure fails to teach:
“…maintain a Bayesian network for a user …”;
“…each threat detector configured to detect a respective condition in network traffic and generate a corresponding signal mapped to a corresponding node…”; and
“…each of the activated subset of nodes associated with a respective one of the triggered threat detectors…”
(e.g. see claims 1, 8, 15)
Specifically, while the applicant’s specification teaches “generating” a Bayesian network for a user (e.g. Fig. 5:500), the applicant fails to teach any aspect of “maintenance” of the graph for a user. The examiner points out that the terms “generate” and “maintain” are not equivalent in meaning.
Specifically, applicant’s disclosure fails to teach any particular configuration of threat detectors, such that each one is configured to detect a respective condition in network traffic. In other words, nowhere does the applicant’s drawings or specification teach or imply that each individual threat detector is configured to detect a separate and distinct, i.e. “respective”, condition in network traffic.
Furthermore, while the applicant’s specification does, in a single instance, reference “signals from threat detectors” (e.g. Specification, par. 27), nowhere does the applicant’s specification teach that generated “signals” are mapped to corresponding nodes.
The examiner notes that the terms “signal”, “message”, and “information” all have separate and distinct meanings within the context of computer communications. Specifically, a “signal” is a physical medium (e.g. voltage, wave, light pulse, etc.) - a detectable and measurable quantity. A “signal” may be said to bear or carry a “message”, which is a structured payload – i.e. data formatted according to a syntax or protocol. Finally the “message” itself may or may not be used to impart “information” – i.e. the cognitive impact or the meaning gained from an interpretation of the message.
In the context of the applicant’s written description, it appears that, at best, the applicant does disclose that threat detectors generate “signals” (e.g. Specification, par. 27). Furthermore, while not explicitly taught by the applicant, it may be suggested or implied that such “signals” are used to bear the plurality of “messages” which are collected by the “trigger collector 300” (e.g. Specification, par. 38, 39; fig. 2:220; fig. 3:300). Finally, while not explicitly taught by the applicant, it may be suggested or implied that the information gained (i.e. “threat”) from the collected messages is transferred from the “threat collector” to a Bayesian model (e.g. Specification, par. 35, fig. 2:220 [Wingdings font/0xE0] 240).
However, the examiner points out that nowhere does it appear that the applicant’s disclosure clearly and specifically illustrate any “mapping” of a “corresponding signal” of a threat detector to a “corresponding node”. That is, the applicant’s disclosure fails to teach any particular configuration of threat detectors, such that each one is configured to generate a corresponding signal that is mapped to a corresponding node.
Furthermore, the applicant’s disclosure fails to teach each node of the activated subset of nodes associated with a respective one of the triggered threat detectors.
Specifically, as shown above, according to the applicant’s original disclosure, all messages from the plurality of threat detectors are aggregated or “collected” by an intermediary “threat collector 300”. The threat collector then appears to transfer threat information, gained from the collected messages, to a Bayesian network comprising nodes. However, nowhere does the applicant ever teach that each node of the Bayesian network is associated with a respective one of the triggered threat detectors.
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 1 – 4, 6 – 11, 13 – 18, 20, and 21 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention.
See above objection to the Specification.
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1 – 4, 6 – 11, 13 – 18, 20, and 21 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Regarding claims 1, 8, and 15, the recitation “… the plurality of nodes in the Bayesian network…” (e.g. claim 1, line 13, 14) lacks antecedent basis within the claims. For the purpose of examination, the examiner presumes the applicant to recite ““… a plurality of nodes in the Bayesian network…”
Regarding claims 1, 8, and 15, the recitations “…maintain a Bayesian network for a user …each threat detector configured to … generate a corresponding signal mapped to a corresponding node … activate, based on corresponding signals from a subset of …threat detectors … a subset of nodes … each node of the activated subset of nodes associated with a respective one of the triggered threat detectors … ” renders the scope of the claims indefinite.
Specifically, the examiner notes that clarity of claim language requires a clear correspondence of the claim language to that of the applicant’s specification (see M.P.E.P. 2173.03).
However, in the instant case the applicant’s disclosure never illustrates “maintaining” Bayesian networks for users, and if the applicant now considers the term “maintaining” to be equivalent to the disclosed “generating”, the examiner points out that the applicant’s disclosure fails to assert such equivalency.
Furthermore, the applicant’s disclosure fails to illustrate the mapping of corresponding signals to corresponding nodes of a Bayesian network. While the applicant’s arguments of record appear to imply that the claimed “signals” are equivalent to the disclosed “messages” (see Remarks, 4/13/26, pg. 2), the examiner points out that nowhere does the applicant’s own written description appear to assert such an equivalency.
Additionally, the examiner notes that the applicant’s written description even fails to illustrate that each of the “messages” themselves are to be mapped to a corresponding node. Rather, the applicant only teaches that the activated nodes are “associated with the threats corresponding to the triggered detectors” (e.g. Specification, par. 39).
Furthermore, while the applicant’s specification does disclose that the plurality of activated nodes are associated with the plurality of triggered detectors (e.g. Specification, par. 50, “…nodes in the network model 240 which are associated with the triggered detectors are activated…”), the applicant fails to teach that that each node is associated with a respective one of the triggered detectors.
Thus, the examiner points out that it is not clear as to the interpretation and scope of the claimed “signals” generated by the threat detectors, and as to how such “signals” are said to be “mapped” to a “corresponding node”, and as to how a subset of nodes are activated “based on corresponding signals from a subset of … threat detectors”.
Depending claims are rejected by virtue of dependency.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1 – 3, 6 – 10, 13 – 17, 20, and 21 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Bassett, US 2019/0373005 A1.
Regarding claim 1, Bassett discloses, as best determined in view of the above noted issues of clarity:
A computer system comprising: a memory; and at least one processor coupled to the memory and configured to (e.g. Bassett, par. 127):
maintain a Bayesian network for a user (e.g. Bassett, par. 17-20, 34 – a Bayesian network is created to model the actions and attributes of a threat actor, i.e. user), the Bayesian network including a plurality of nodes and configured to store probabilistic information associated with the user and known threats (e.g. Bassett, par. 19, 20, 37 - 39; fig. 1);
detect triggering of one or more of a plurality of threat detectors (e.g. Bassett, par. 6, 33, 65, 94; fig. 6:605; claim 3 - Herein one or more “threat detectors” (i.e. various sensors and attack detector) are “triggered” by the observation of data, conditions, and events within a network), each threat detector configured to detect a respective condition in network traffic (e.g. Bassett, claim 3; par. 94, 95, 101) and generate a corresponding signal mapped to a corresponding node of the Bayesian network for the user (e.g. Bassett, Abstract; par. 65 – observations from the “threat detectors” are mapped to respective nodes of a graph), wherein at least one threat detector is configured to detect one or more properties of the user associated with an action corresponding to the network traffic (e.g. Bassett, Abstract; par. 71, 94, 95, 101);
activate, based on corresponding signals from a subset of the plurality of threat detectors including the at least one threat detector, a subset of nodes from the plurality of nodes in the Bayesian network, each node of the activated subset of nodes associated with a respective one of the triggered threat detectors (e.g. Bassett, par. 33, 34, 58, 59, 61, 81, 93 - 96; fig. 1). Herein, one or more likely attack paths of nodes (i.e. a subset of nodes) are identified (i.e. “activated”).
calculate a probability of malicious action using the Bayesian network to combine probabilities associated with the activated subset of nodes, wherein the probability of the malicious action is calculated based at least in part on the one or more properties of the user associated with the action corresponding to the network traffic (e.g. Bassett, par. 56, 60, 61, 76 – 81, 91, 93- 95, 101). Herein, conditional probability tables, CPTs, are calculated for the identified nodes within the attack path – the attack paths being based upon the hacker’s malicious actions within the network.
determine that the probability exceeds a threshold value (e.g. Bassett, par. 18, 81, 86, 88, 96, 97, 99, 101). Herein, attack likelihoods (i.e. probabilities) are compared to various threshold values, such as previous likelihoods values for the prioritization of risk, qualitative values (e.g. low, medium, high risks), and/or differential measurements, in order to determine if an attack has/or is likely to have occurred.
and perform a security action in response to the determination (e.g. Bassett, par. 22, 98, 99).
Regarding claim 2, Bassett discloses:
wherein each node of the plurality of nodes of the Bayesian network is configured to provide a probability of detection and a probability of false alarm of the threat associated with the each node (e.g. Bassett, par. 41 – 43, 56).
Regarding claim 3, Bassett discloses:
wherein the each node is associated with a threat objective and with one or more threat techniques, the threat techniques associated with the threat objective and with one of the threat detectors (e.g. Bassett, par. 6, 17, 18, 94; table 5). Herein, attributes (i.e. threat techniques) of a graph node are associated with corresponding attackers/threat actors (i.e. threat objective), each of which are detected by network sensors (i.e. threat detectors).
Regarding claim 6, Bassett discloses:
wherein the at least one processor is further configured to select the threshold value based on a tradeoff between a probability of detection of the malicious action and a probability of false alarm of the malicious action (e.g. Bassett, par. 18, 81, 86, 88, 96, 97, 99, 101). Herein, attack threshold values (e.g. low, medium, high risks and/or prioritized probability rankings, and/or differential measurements) are all based upon an attack probability, i.e. a tradeoff or likelihood between an attack being correctly detected or falsely detected (i.e. “false alarm”).
Regarding claim 7, Bassett discloses:
wherein the at least one processor is further configured to create and update the plurality of nodes of the Bayesian network based on provisioning of threat detectors and provisioning of threat detector performance data (e.g. Bassett, par. 6, 33, 65, 79, 94; fig. 6:605; claim 3). Herein, nodes of the Bayesian network are created and updated through the detections of the GUI and system sensors, i.e. “threat detectors”.
Regarding claims 8 – 10, 13 – 17, 20, and 21, they are method and medium claims essentially corresponding to the system claims above, and they are rejected, at least, for the same reasons.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 5, 12, and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Bassett, US 2019/0373005 A1 in view of Mittal et al. (Mittal), US 2025/0007937 A1.
Regarding claim 5, Bassett discloses a system for using Bayesian probability to detect attacks based upon collected information, however does not appear to explicitly teach that such collected information could include a geolocation of the user or reputation data associated with an internet provider employed by the user.
However, Mittal also teaches a system for using Bayesian probability to detect attacks based upon collected information (e.g. Mittal, par. 79), and further teaches that such collected information can include a geolocation of the user and reputation data associated with an internet provider employed by the user (e.g. Mittal, par. 76, e.g. geo-location and the reputation of the attackers IP addresses used to provide connection to the internet, i.e. reputation data associated with the attacker’s internet provider).
It would have been obvious to include the teachings of Mittal for collecting information such as a user’s geolocation and data associated with a reputation of an internet provider within the system of Bassett for using collected information to detect attacks using Bayesian probability. This would have been obvious because one of ordinary skill in the art would have been motivated by the teachings that better resource protection can be achieved by collecting and using such metadata (e.g. Mittal, par. 73 – 76).
Thus, the combination enables
wherein the properties include a geolocation of the user and reputation data associated with an internet provider employed by the user (e.g. Mittal, par. 76).
Regarding claims 12 and 19, they are method and medium claims essentially corresponding to the system claims above, and they are rejected, at least, for the same reasons.
Response to Arguments
Applicant's arguments filed 4/13/26 have been fully considered but they are not persuasive.
Applicant argues or alleges essentially that:
…
As shown at least in FIG. 1, threat detectors 120, 130, 150 are shown as being included in the network 140, along with on the respective devices 110a, 110b. The Detailed Description states that "the infrastructure of the network 140 may include additional threat detectors 150 configured to monitor and detect threats in the network traffic." [0029]. Thus, FIG. 1, in combination with the related description, clearly shows and describes threat detectors 150 which monitor network traffic. …
…
(Remarks, pg. 2)
Examiner respectfully responds:
The examiner respectfully disagrees. While figure 1 might be said to illustrate distinct threat detectors associated with respective devices, figure 1 does not illustrate the association of distinct threat detectors with “respective” conditions of network traffic. In other words, nowhere does the applicant’s drawings or specification teach or imply that each individual threat detector is configured to detect a separate and distinct (i.e. “respective”) condition in network traffic.
Applicant argues or alleges essentially that:
…
… In FIG. 3, for example, "a detector trigger collector 300 is configured to detect the triggering 200 of one or more threat detectors, from user devices, the network, or any other source where a threat detector may be employed. For example, threat detectors may communicate detected threats as messages transmitted over the network or through an application programming interface (API). The node activator 310 is configured to activate nodes in the Bayesian network ... based on the triggered detectors. The nodes to be activated are associated with the threats corresponding to the triggered detectors." [0039]. …
…
(Remarks, pg. 2)
Examiner respectfully responds:
The examiner respectfully disagrees.
First, the examiner notes that applicant’s remarks appear unpersuasive because “signals” are not equivalent in meaning to that of “messages”. Furthermore, the applicant’s own disclosure fails to teach that the “signals” of paragraph [27] of applicant’s specification are the same as the “messages” of paragraph [39]. Additionally, even if such an equivalency could be asserted, the examiner notes that the applicant’s specification does not teach that each individual “message” is mapped to a corresponding one of a node.
Second, the examiner notes that while the applicant’s specification does disclose that the plurality of activated nodes are associated with the plurality of triggered detectors (e.g. Specification, par. 50, “…nodes in the network model 240 which are associated with the triggered detectors are activated…”), the applicant fails to teach that that each individual node is associated with a respective one of the triggered detectors.
Applicant argues or alleges essentially that:
…
… Additionally, and with respect to the “respective condition” in network traffic, the Specification states that the “Bayesian network model is configured to jointly assess a wide range of factors including: (1) signals from threat detectors related to user actions and/or unusual behaviors ; (2) threat intelligence (e.g., metadata ) about the users and the internet providers (IP) that they are using …” ¶[0027]. Further, FIG. 9 and the related description describes various nodes which receive triggers from corresponding detectors based conditions of network traffic. For example, paragraph [0060] states in part that “The user property detector node 905 is associated with a binary random variable indicating whether a user property based detector is triggered . User property based detectors are configured to decide user maliciousness based on properties of the user such as unusual or unexpected geolocation or probabilistic intelligence such as reputation data of the user’s IP…” Thus, the Specification clearly supports threat detectors providing signaling related to conditions, such as user actions and/or unusual behavior.
…
(Remarks, pg. 3, 4)
Examiner respectfully responds:
The examiner respectfully disagrees. Specifically, the term “respective” means belonging or relating separately to the individual. While the applicant’s specification appears does illustrate that a plurality of network conditions can be detected by the plurality of threat detectors, the applicant fails to specifically point out how each individual threat detector is configured to detect its own separate and individual (i.e. “respective”) network condition.
Applicant argues or alleges essentially that:
…
However, while the cited passages describe a Bayesian network generally, the cited passages are silent as to any Bayesian network which is maintained for a user as recited in amended claim 1. Additionally, and given these deficiencies … In particular, because Bassett does not disclose any Bayesian network being maintained for the user as claimed in claim 1, Bassett does not and cannot disclose any usage of such a Bayesian network for the user as claimed.
…
(Remarks, pg. 5)
Examiner respectfully responds:
The examiner respectfully disagrees. Specifically, at least to the extent that the applicant appears to regard the generation of a Bayesian network to be the same as the maintenance of a Bayesian network, it is noted that the prior art teaches the maintenance of a Bayesian network for one or more network users (e.g. an threat actor) (e.g. Bassett, par. 17-20, 34, 37 - 39; fig. 1 – a Bayesian network is created to model the actions and attributes of a threat actor, i.e. user).
Additionally, the examiner notes that Bassett clearly teaches that the generated Bayesian network which models the threat actor is later analyzed by an analyst, thus it is clearly preserved or “maintained” (e.g. Bassett, par. 19, 20).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JEFFERY L WILLIAMS whose telephone number is (571)272-7965. The examiner can normally be reached 7:30 am - 4:00 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Farid Homayounmehr can be reached at 571-272-3739. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/JEFFERY L WILLIAMS/Primary Examiner, Art Unit 2495