DETAILED ACTION
In a communication received on 27 May 2026, the applicants canceled claims 2, 4, 12, and 14 and amended claims 1, 3, 8, 11, 13, and 18.
Claims 1, 3, 7-11, 13 and 17-20 are pending.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant’s arguments with respect to claim(s) 1 and 11 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1, 3, 7-11, 13 and 17-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Gaber et al. (US 2022/0405386 A1) in view of Scherman et al. (US 2018/0124073 A1) and Machlica et al. (US 2017/0134404 A1), and further in view of Miller et al. (US 2019/0188212 A1).
With respect to claim 1, Gaber discloses: a method for detecting a network attack based on a fusion feature vector (i.e., cyberattack prediction using several trained models whose outputs are merged into a feature vector and supplied to an ensemble model in Gaber, ¶¶0002, 0016, 0022), comprising:
generating fusion feature vectors based on the extracted feature vectors; (i.e., merge outputs from individual models into a feature vector used by the ensemble model in Gaber, ¶0022)
performing training using the generated fusion feature vectors (i.e., train the ensemble model using the feature vector formed from individual-model predictions and accuracy measures in Gaber, ¶0022);
detecting the network attack based on at least one of the generated fusion feature vectors (i.e., obtain an ensemble prediction and classify cyberattacks from the union of individual-model outputs in Gaber, ¶¶0016, 0022).
Gaber discloses ensemble-model feature intake, merged-output training, and cyberattack prediction (¶¶0016, 0022, 0032). Gaber do(es) not explicitly disclose the following. Scherman, in order to improve network-security speed and accuracy by training attack models on windowed metrics from known benign and malicious IP flows (¶¶0013, 0024, 0037-0039), discloses:
extracting feature vectors corresponding to a preset unit time from network traffic (i.e., collect network IP-flow records and derive tuple metrics for flows divided into configured timeframes in Scherman, ¶¶0015, 0021, 0033)
wherein the features of the flow set include statistics information on protocols, (i.e., protocol-keyed flow sets summarized with TCP-flag ratios and entropy, packet-size statistics, timing, and flow counts in Scherman, ¶¶0021, 0023, 0033);
the second feature vector is a flow feature vector corresponding to a set of feature vectors extracted from a single flow, and is expressed as FF(w)_i^m, FF being a flow feature and m being an m-th feature value of flow i of window w, and (i.e., group packets into one flow by source, destination, and protocol and calculate a timeframe-specific feature tuple in Scherman, ¶¶0021, 0023, 0033);
the third feature vector is an environment feature vector that includes a total number of flows, a variety of destination IP addresses, a plurality of states and a proportion of active flows among IP address pairs, and is expressed as EF_w^n, EF being an environment feature, and n being an n-th feature value of window w. (i.e., flow aggregation using flow counts, destination-group observations, TCP-state ratios, direction, and packet statistics in Scherman, ¶¶0023-0024).
Based on Gaber in view of Scherman, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Scherman to improve upon those of Gaber in order to improve network-security speed and accuracy by training attack models on windowed metrics from known benign and malicious IP flows.
Gaber discloses the ensemble-model merged-output feature vector (¶¶0016, 0022). Gaber and Scherman do(es) not explicitly disclose the following. Machlica, in order to improve malicious-traffic classification and generalization by computing hierarchical context features from packet-flow logs (¶¶0015-0016, 0043-0044), discloses:
wherein the feature vectors include a first feature vector, a second feature vector, and a third feature vector extracted from a flow set within the preset unit time (i.e., multiple hierarchical feature-vector levels derived from packet-flow data in one time window in Machlica, ¶¶0012, 0016, 0043-0045),
wherein the third feature vector is generated based on a feature set representing features of the flow set within the preset unit time (i.e., a final window-level traffic vector produced by aggregating features from lower-level flow groupings in Machlica, ¶¶0043-0045),
the generating the fusion feature vectors includes using common variables present in the first feature vector, the second feature vector and the third feature vector (i.e., hierarchical matrices reuse time-window and traffic-group indices when selecting and aggregating vectors in Machlica, ¶¶0041, 0043), and
generating a two-dimensional feature set (X * Y) for each of flows in a time window (i.e., form an N-by-T data matrix of per-log attribute vectors for traffic occurring in time window t in Machlica, ¶¶0041, 0044-0045), and
w and i are among the common variables common to at least two of the first feature vector, the second feature vector and the third feature vector, the at least two of the first feature vector, the second feature vector and the third feature vector are fused using the common variables (i.e., align and aggregate hierarchical vectors by the same time-window and flow-group context in Machlica, ¶¶0041, 0043-0045).
Based on Gaber in view of Scherman, and further in view of Machlica, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Machlica to improve upon those of Gaber in order to improve malicious-traffic classification and generalization by computing hierarchical context features from packet-flow logs.
Gaber discloses ensemble-model generic input features (¶¶0016, 0022, 0032). Gaber, Scherman, and Machlica do(es) not explicitly disclose the following. Miller, in order to preserve bidirectional flow information and support prompt anomaly detection by using a fixed, ordered first-N-packet representation (¶¶0066-0067, 0130), discloses:
wherein X is set equal to only a first n packets in each flow (i.e., restrict each flow vector to only the first configured K or N packets in the bidirectional flow in Miller, ¶¶0066, 0130),
data included in each element of the two-dimensional feature set is represented as SF(w, i)_x^y, where SF(w, i)_x^y is a y-th feature value of packet x of flow i in window w, SF is a sequence feature, w is a time window number, i is a flow number, x is a packet number, y is a feature number (i.e., fixed packet positions encode per-packet size, direction, header, and timing within each flow and hourly batch in Miller, ¶¶0066-0067, 0130-0131),
the first feature vector is a packet feature vector corresponding to a set of feature vectors extracted from respective packets, (i.e., form each flow representation from ordered feature information representing the respective packets in Miller, ¶0066).
Based on Gaber in view of Scherman and Machlica, and further in view of Miller, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Miller to improve upon those of Gaber in order to preserve bidirectional flow information and support prompt anomaly detection by using a fixed, ordered first-N-packet representation.
With respect to claim 3, Gaber discloses an individual ML model outputs prediction based on acquiring any type or category of feature relevant for prediction, ML model output are features merged into a feature vector and classifying the union of the subsets of individual models features (¶0022, ¶0023, ¶0032). Gaber do(es) not explicitly disclose the following. Scherman, in order to identify specific benign or malicious users with attack models trained with netflow data/metrics (¶0024), discloses: the method of claim 1, wherein the first feature vector is generated based on a feature set representing features of a preset number of packets for each of the flows (i.e., determining a ratio of TCP flags from the respective packets of the flow; a preset number of packets is suggested by dividing the tuple into a timeframe and an average time between packets as collected characteristics in Scherman, ¶0017, ¶0023, ¶0033).
Based on Gaber in view of Scherman, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Scherman to improve upon those of Gaber in order to identify specific benign or malicious users with attack models trained with netflow data/metrics.
With respect to claim 7, Gaber discloses features correspond to any type or category of information relevant for ML model prediction context, an important feature being a feature that is statistically significant impact on the result of the ML model (¶0032, ¶0034). Gaber do(es) not explicitly disclose the following. Scherman, in order to identify specific benign or malicious users with attack models trained with netflow data/metrics (¶0024), discloses: the method of claim 3, wherein features of a packet include
a size of the packet (i.e., packet sizes of the flow in Scherman, ¶0023),
a size of an IP packet header (i.e., determine several bits of header for flags to identify features of the communication in Scherman, ¶0017),
an inter-arrival time (i.e., time between requests and communications in Scherman, ¶0023),
a direction of the packet (i.e., metrics include a flow direction to/from malicious party in Scherman, ¶0023),
an inter-arrival time according to the direction of the packet (i.e., time between requests, determining the flow direction to/from, analyzing inbound and outbound separately in Scherman, ¶0023), and
a flag value of the packet (i.e., TCP flags corresponding to the type of communication in Scherman, ¶0017, ¶0023).
Based on Gaber in view of Scherman, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Scherman to improve upon those of Gaber in order to identify specific benign or malicious users with attack models trained with netflow data/metrics.
With respect to claim 8, Gaber discloses features correspond to any type or category of information relevant for ML model prediction context, an important feature being a feature that is statistically significant impact on the result of the ML model (¶0032, ¶0034). Gaber do(es) not explicitly disclose the following. Scherman, in order to identify specific benign or malicious users with attack models trained with netflow data/metrics (¶0024), discloses: the method of claim 1, wherein the features of the flows include
basic flow information (i.e., flow information and groupings of IP packets by source and destination in Scherman, ¶0021),
flow duration (i.e., time between communications of TCP/IP communications flows in Scherman, ¶0023),
a flow direction (i.e., determining communication direction to/from inbound/outbound of malicious users in Scherman, ¶0023),
a flow state (i.e., changes in TCP flags of incoming and outgoing flows in Scherman, ¶0023), and
a number of packets (i.e., number of packets suggested by performing an average of packet sizes as part of feature data collected in Scherman, ¶0023, ¶0024).
Based on Gaber in view of Scherman, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Scherman to improve upon those of Gaber in order to identify specific benign or malicious users with attack models trained with netflow data/metrics.
With respect to claim 9, Gaber discloses features correspond to any type or category of information relevant for ML model prediction context, an important feature being a feature that is statistically significant impact on the result of the ML model (¶0032, ¶0034). Gaber do(es) not explicitly disclose the following. Scherman, in order to identify specific benign or malicious users with attack models trained with netflow data/metrics (¶0024), discloses: the method of claim 1, wherein the features of the flow set further include
a number of flows (i.e., number of incoming and outgoing flows from the cloud service and client device in Scherman, ¶0023),
variety of destination IP addresses (i.e., metrics gathered for flows from client device to all servers in Scherman, ¶0023), and
statistical information on flows in the flow set (i.e., average packet sizes of flows, aggregated flow metrics averaged over the servers in Scherman, ¶0023, ¶0024).
Based on Gaber in view of Scherman, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Scherman to improve upon those of Gaber in order to identify specific benign or malicious users with attack models trained with netflow data/metrics.
With respect to claim 10, Gaber discloses features correspond to any type or category of information relevant for ML model prediction context, an important feature being a feature that is statistically significant impact on the result of the ML model (¶0032, ¶0034). Gaber do(es) not explicitly disclose the following. Scherman, in order to identify specific benign or malicious users with attack models trained with netflow data/metrics (¶0024), discloses: the method of claim 8, wherein the basic flow information includes a source IP address, a source port, a destination IP address, a destination port, and protocol information (i.e., IP flow packet information includes groupings of packets that share source, destination, addresses and protocol; SYN flags correspond to port information and is a known attack vector in scanning ports to attack in Scherman, ¶0021, ¶0023).
Based on Gaber in view of Scherman, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Scherman to improve upon those of Gaber in order to identify specific benign or malicious users with attack models trained with netflow data/metrics.
With respect to claim 11, the limitation(s) of claim 11 are similar to those of claim(s) 1. Therefore, claim 11 is rejected with the same reasoning as claim(s) 1.
With respect to claim 13, the limitation(s) of claim 13 are similar to those of claim(s) 3. Therefore, claim 13 is rejected with the same reasoning as claim(s) 3.
With respect to claim 17, the limitation(s) of claim 17 are similar to those of claim(s) 7. Therefore, claim 17 is rejected with the same reasoning as claim(s) 7.
With respect to claim 18, the limitation(s) of claim 18 are similar to those of claim(s) 8. Therefore, claim 18 is rejected with the same reasoning as claim(s) 8.
With respect to claim 19, the limitation(s) of claim 19 are similar to those of claim(s) 9. Therefore, claim 19 is rejected with the same reasoning as claim(s) 9.
With respect to claim 20, the limitation(s) of claim 20 are similar to those of claim(s) 10. Therefore, claim 20 is rejected with the same reasoning as claim(s) 10.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHERMAN L LIN whose telephone number is (571)270-7446. The examiner can normally be reached Monday through Friday 9:00 AM - 5:00 PM (Eastern).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Joon Hwang can be reached on 571-272-4036. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
Sherman Lin
8/12/2026
/S. L./Examiner, Art Unit 2447
/JOON H HWANG/Supervisory Patent Examiner, Art Unit 2447