Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant’s submission filed on 3/6/2026, for application 18/016,402 has been entered.
This Office Action is in response to the amendment filed 3/6/2026 for application 18/016,402.
Claims 1-5, 7, 10-14, 16, and 18-20 are currently pending; claim 6 has been canceled; claims 1, 11, 16, and 18 have been amended; claims 8, 9, 15, and 17 have been canceled; claims 1, 11, 16, , and 18 are the independent claims; claims 1-5, 7, 10-14, 16, and 18-20 have been examined. This Action is made non-FINAL.
Response to Arguments
Applicants’ arguments, see Applicant Arguments/Remarks Made in an Amendment, filed 3/6/2026, with respect to the rejections of claims 1-5, 7, 10-14, 16, and 18-20 have been fully considered but are not persuasive.
Applicant asserts as follows: The Applicant submits that using information in at least one created screened provenance graph or one or more created final taint sets to identify at sensitive data or sensitive data flow paths associated with data related to the kernel system call events that should be tracked cannot be performed in the human mind and, especially that causing systems in a container network associated with the containerized applications to track at least one of the sensitive data or data through the sensitive data flow paths in the at least one container network cannot be performed in the human mind.
Examiner respectfully disagrees. As recited in the independent claims 1, 11 and 16, the claimed system/method/non-transitory computer readable medium comprises the operations: “creat[ing] a provenance graph of vertices and edges …” “creat[ing] a screens provenance graph,” “apply[ing] the information … to track a flow of sensitive data;” “check[ing] ancestral lineage of the vertices and edges …” “determining [] whether a child of an edge being processed is a flagged destination …” “determining [] whether a parent is in any of the taint sets …” and “logging an entry in a log file …” Broadly interpreted, the aforementioned operations (i.e., creating, applying information to track a flow of sensitive data, checking, determining and logging, etc.,) are mental processes as said operations could be performed in the human mind or using pencil and paper. It’s also noted that the claims recite additional limitation/elements (i.e., tracking system, storage, processor, network, device, memory etc.,). However, said additional elements are recited at a high-level of generality (i.e., as a generic computing device performing a generic computer functions) such that it amounts no more than mere instructions to apply the exception or abstract idea using generic computer components. Accordingly, these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. The claims do not include additional limitations/embodiments that are sufficient to amount to significantly more than the judicial exception because the additional elements when considered both individually and as an ordered combination do not amount to significantly more than the abstract idea. As mentioned above, although the claims recite additional elements, said elements taken individually or as a combination, do not result in the claim amounting to significantly more than the abstract idea because as the additional elements perform generic computer functions routinely used in information technology field. Therefore, the claim is directed to non-statutory subject matter.
Applicant asserts as follows: In addition, the Applicant respectfully submits that the technical features of the Applicant's independent claims integrate any portion of the Applicant's claims that could be considered a judicial exception into a practical application. Specifically, the law states that integration into a practical application requires the additional element(s) to apply, rely on, or use the judicial exception in a manner that imposes a meaningful limit on the judicial exception, such that the claim is more than a drafting effort designed to monopolize the exception.
Examiner respectfully disagrees. Creating a graph is a mental activity that may be accomplished with a pen and paper. Said abstract idea and/or judicial exception is not integrated into a practical application as the claim does not recite any other active steps that could be considered that the abstract idea is being integrated into a practical application. It’s noted that the claim recites the steps of “receiv[ing] audit records;” “receiving a network tagged specification file;” “user the information…”, “in response, to cause systems… to track”, and “stor[ing] the taint set of sensitive data.” However, said steps are not sufficient to consider that the abstract idea is being interpreted into a practical application as the aforementioned steps are recited at a high level of generality in gathering/processing/storing information, which are a form of insignificant extra-solution activity. It’s also noted that the claims recite additional limitation/elements (i.e., tracking system, storage, processor, network, device, memory etc.,). However, said additional elements are recited at a high-level of generality (i.e., as a generic computing device performing a generic computer functions, check ancestral lineage, determining whether a child, determining whether a parent; determin[ing] whether a parent is in any of the taint sets stored in the taint storage … and log[ging] an entry in a log file.) such that it amounts no more than mere instructions to apply the exception or abstract idea using generic computer components. Accordingly, these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea.
Applicant asserts as follows: The Applicant further submits that the features of the Applicant's claims provide improvements to the functioning of a computer and as such are patentable under 35 USC 101. More specifically, the technical features of the Applicant's claims which include, inter alia to "create a screened provenance graph that includes data deemed sensitive by performing a first level of pruning of the provenance graph using one or more storagescreens", "create one or more final taints set of sensitive data to be tracked at a container level that includes vertices and edges that are descended from a particular sensitive source using one or more dependency checkers", and "use the information in at least one of the created screened provenance graph or the one or more created final taint sets to identify at least one of sensitive data or sensitive data flow paths associated with data related to the kernel system call events that should be tracked and, in response, to cause systems in at least one container network associated with the containerized applications to track at least one of the sensitive data or data through the sensitive data flow paths in the at least one container network " enable a computer to now provide dataflow tracking capabilities for computers that implement containers and to now provide the tracking of sensitive dataflows across containers, which was not possible for computers to perform at the time of the filing of the Applicant's invention.
Examiner respectfully disagrees. It’s also noted that the claims recite additional limitation/elements (i.e., tracking system, storage, processor, network, device, memory etc.,). However, said additional elements are recited at a high-level of generality (i.e., as a generic computing device performing a generic computer functions) such that it amounts no more than mere instructions to apply the exception or abstract idea using generic computer components. Accordingly, these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. The claims do not include additional limitations/embodiments that are sufficient to amount to significantly more than the judicial exception because the additional elements when considered both individually and as an ordered combination do not amount to significantly more than the abstract idea. As mentioned above, although the claims recite additional elements, said elements taken individually or as a combination, do not result in the claim amounting to significantly more than the abstract idea because as the additional elements perform generic computer functions routinely used in information technology field. Therefore, the claim is directed to non-statutory subject matter.
Applicant asserts as follows: The Applicant respectfully submits that the references cited by the Examiner, alone or in any allowable combination, fail to teach or suggest all of the limitations of at least the Applicant's independent claim 1, which recites, inter alia "using the information in at least one of the created screened provenance graph or the one or more created final taint sets to identify at least one of sensitive data or sensitive data flow paths associated with data related to the kernel system call events that should be tracked and, in response, to cause systems in at least one container network associated with the containerized applications to track at least one of the sensitive data or data through the sensitive data flow paths in the at least one container network" and "wherein the one or more dependency checkers are configured to check ancestral lineage of the vertices and edges included in the screened provenance graph and keep track of a sub-graph that is descended from every sensitive vertex included in the screened provenance graph by: determining, for each edge in the screened provenance graph, whether a child of an edge being processed is a flagged destination within the flagged destination configuration file; determining whether a parent is in any of the taint sets stored in the taint storage if the child is a flagged destination; and logging an entry in a log file that indicates that there was a sensitive source that was associated with the flagged destination if the parent is in any of the taint sets".
Examiner respectfully submits that regarding claim 1, Sekar discloses, paragraphs 0366, 0387, and 0073, a taint tracking system for providing sensitive dataflow tracking for containerized applications, comprising by disclosing computer, methods, computer readable media; paragraph 0387, computing device, paragraph 0073, taint detection checks; paragraph 0085, receive audit records including container information by disclosing reported in an audit log; paragraphs 0342, 0318, and 0129,to create a provenance graph of vertices and edges associated with kernel system call events being monitored based on the received audit records by disclosing tracking, trace back to root causes, logging system, kernel updates: provenance tags derives from audit history; paragraph 0199, (1) create a screened provenance graph that includes data deemed sensitive by performing a first level of pruning of the provenance graph using one or more storage screens, by disclosing graph representation, merging, pruning, writing; paragraphs 0072 and 0079, (2) create one or more final taints set of sensitive data to be tracked at a container level that includes vertices and edges that are descended from a particular sensitive source using one or more dependency checkers by disclosing tags, data provenance from audit logs, flow labels; identify sources of the attack); paragraph 0072, store the taint sets of sensitive data to be tracked at the container level by disclosing audit log, taint tag; paragraphs 0271, 0072, 0345, wherein the one or more dependency checkers are configured to check ancestral lineage of the vertices and edges included in the screened provenance graph and keep track of a sub-graph that is descended from every sensitive vertex included in the screened provenance graph by disclosing descendants; graph, sub-graph, real-tie detection from which scenario sub-graphs are extracted; paragraphs 0182 and 0202, determining, for each edge in the screened provenance graph, whether a child of an edge being processed is a flagged destination within the flagged destination configuration file by disclosing dependency edges, flagged address, flagged tag); paragraph 0198, determining whether a parent is in any of the taint sets stored in the taint storage if the child is a flagged destination by disclosing edges to be included in final compact scenario representation; paragraphs 0078 and 0079, logging an entry in a log file that indicates that there was a sensitive source that was associated with the flagged destination if the parent is in any of the taint sets by disclosing events collected by logging system; paragraphs 0085-0086, storing the taint sets of sensitive data to be tracked at the container level within a taint storage by disclosing storage, audit logs. Sekar discloses backward analysis and forward analysis in paragraphs 0238, 0239, 0250, and 0265, and dependencies. Source vertices disclosed in paragraph 0239 of Sekar corresponds to ancestral lineage. Sekar discloses in paragraph 0216 identifying paths that connect suspect nodes and in paragraph 0198 discloses edges through which confidential data flows. Sekar in paragraph 0270 and 0275 discloses tracking to edges indicate instances of untrusted code. Yermakov discloses, paragraph 0035, a taint tracking system for providing sensitive dataflow tracking for containerized applications, comprising by disclosing virtual containers configured to protect resource, tainted data; paragraph 0035, receive audit records including container information to create a provenance graph of vertices and edges associated with kernel system call events being monitored based on the received audit records by disclosing virtual containers configured to protect resource, tainted data; paragraph 0035, create one or more final taints set of sensitive data to be tracked at a container level that includes vertices and edges that are descended from a particular sensitive source using one or more dependency checkers by disclosing virtual containers configured to protect resource, tainted data; paragraphs 0034 and 0035, use the information in at least one of the created screened provenance graph or the one or more created final taint sets to identify at least one of sensitive data or sensitive data flow paths associated with data related to the kernel system call events that should be tracked by disclosing kernel, sensitive information initially tainted by gateway or client device, tainting marked so that it can be tracked, tainted data as sensitive information, virtual containers configured to protect resources. Newly cited reference, Gervais, discloses, paragraphs 0019, 0036, 0038, 0049, 0039, in response, to cause systems in at least one container network associated with the containerized applications to track at least one of the sensitive data or data through the sensitive data flow paths in the at least one container network by disclosing network domains, events, kernel, event tracking, network connection events, agent resides on both source and destination server, tracking is automated; containerization systems, cloud information systems, containers virtualize access to resources, encapsulate software into containers; kernel based event monitoring.
The Examiner respectfully suggests that the claims be further amended and details in the specification be incorporated to distinguish the claimed invention over prior art of record. Should the Applicant desire an interview to further clarify the claim interpretation/rejections, please contact the Examiner at (571) 272 5368 to schedule an interview.
Claim Interpretation
The following is a quotation of 35 U.S.C. 112(f):
(f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph:
An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked.
As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph:
(A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function;
(B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and
(C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function.
Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function.
Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function.
Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action.
This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation(s) is/are: “NTPC systems are configured to include labels” recited in claim 10.
Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof. Paragraphs 0029 and 0084 of Applicant’s disclosure discloses storage devices, RAM, ROM, kernel.
If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-5 and 7-20 are rejected under 35 U.S.C. 101 as being directed to non-statutory subject matter as being directed to an abstract idea without being integrated into a practical application or significantly more.
Regarding claims 1, 11, 16 and 18, Claims 1, 11 and 16 recite the steps of “creat[ing] a provenance graph of vertices and edges;” “creat[ing] a screened provenance graph;” “creat[ing] one or more finale taint set of sensitive data.” Claim 18 recites the steps of “detecting [] sensitive data …” and “generating taints sets.” Broadly interpreted, the aforementioned steps are directed to mental processes as said steps could be performed in the human mind. Therefore, the claims recite an abstract idea.
Said abstract idea and/or judicial exception is not integrated into a practical application as the claim does not recite any other active steps that could be considered that the abstract idea is being integrated into a practical application. It’s noted that the claim recites the steps of “receiv[ing] audit records;” “receiving a network tagged specification file;” “user the information…”, “in response, to cause systems… to track”, and “stor[ing] the taint set of sensitive data.” However, said steps are not sufficient to consider that the abstract idea is being interpreted into a practical application as the aforementioned steps are recited at a high level of generality in gathering/processing/storing information, which are a form of insignificant extra-solution activity.
It’s also noted that the claims recite additional limitation/elements (i.e., tracking system, storage, processor, network, device, memory etc.,). However, said additional elements are recited at a high-level of generality (i.e., as a generic computing device performing a generic computer functions, check ancestral lineage, determining whether a child, determining whether a parent; determin[ing] whether a parent is in any of the taint sets stored in the taint storage … and log[ging] an entry in a log file.) such that it amounts no more than mere instructions to apply the exception or abstract idea using generic computer components. Accordingly, these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea.
The claims do not include additional limitations/embodiments that are sufficient to amount to significantly more than the judicial exception because the additional elements when considered both individually and as an ordered combination do not amount to significantly more than the abstract idea. As mentioned above, although the claims recite additional elements, said elements taken individually or as a combination, do not result in the claim amounting to significantly more than the abstract idea because as the additional elements perform generic computer functions routinely used in information technology field. Therefore, the claim is directed to non-statutory subject matter.
Regarding claims 2-5, 7, 10, 12-14, and 19-20, Claims 2-10, 12-15 and 19-20 are also rejected under 35 U.S.C. 101 as being directed to non-statutory subject matter for the same reasons addressed above as the claims recite an abstract idea and the claims do not positively recite any other operations that could be considered as the abstract idea is being integrated into a practical application or significantly more. It’s noted that claim 2 recites the limitations: “generat[ing] one or more synthesized audit records …;” Claim 14 recites the limitations “checking ancestral lineage…” and “tracking a sub-graph …” etc., Said steps are either directed to mental processes and/or in a form of insignificant extra-solution activities. Therefore, claims 2-3, 5-11 and 13-16 are also rejected under 35 U.S.C. 101 as being directed to non-statutory subject matter.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 18-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor, or for pre-AIA the applicant regards as the invention.
Regarding claim 18; Claim 18 is found indefinite because metes and bound of the claim are not clearly defined. Claim 18 is directed to a method claim; However, the claim also recites “deploying one or more networked taint tracking systems in accordance with the system of claim 1.” (emphasis added). As the method claim of claim 18 refers to limitations recited in a system claim of claim 1, it’s unclear how embodiments and corresponding functions of claim 1 further defines metes and bounds of the method of claim 18. As a result, claim 18 is found indefinite as metes and bounds of the claim is not clearly defined; (see MPEP 2173.05(f) for details).
Regarding claims 19-20; Claims 19-20 are dependent on claim 18, and therefore inherit 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph issues of the independent claim.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically discloses as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claims 1, 3-5, 7, 11-14, 16, and 18-20 are rejected under 35 U.S.C. 103 as being unpatentable over Sekar (US20200059481) filed August 19, 2019, in view of Yermakov (US20110307951), filed June 9,2011, and Gervais (US20180176244), filed December 19, 2017.
Regarding claim 1, Sekar discloses a taint tracking system for providing sensitive dataflow tracking for containerized applications, comprising (Sekar, paragraph 0366, computer, methods, computer readable media; paragraph 0387, computing device, paragraph 0073, taint detection checks);
a processor; and (Sekar, paragraph 0366, processor);
a memory coupled to the processor, the memory having stored therein at least one of programs or instructions executable by the processor to configure the taint tracking system to (Sekar, paragraph 0366, memory);
receive audit records including container information (Sekar, paragraph 0085, reported in an audit log);
to create a provenance graph of vertices and edges associated with kernel system call events being monitored based on the received audit records (Sekar, paragraph 0342, tracking, trace back to root causes, logging system; paragraph 0318, kernel updates: paragraph 0129, provenance tags derived from audit history);
create a screened provenance graph that includes data deemed sensitive by performing a first level of pruning of the provenance graph using one or more storage screens, and (Sekar, paragraph 0199, graph representation, merging, pruning, writing);
create one or more final taints set of sensitive data to be tracked at a container level that includes vertices and edges that are descended from a particular sensitive source using one or more dependency checkers (Sekar, paragraph 0072, tags, data provenance from audit logs, flow labels; paragraph 0079, identify sources of the attack);
wherein the one or more dependency checkers are configured to check ancestral lineage of the vertices and edges included in the screened provenance graph and keep track of a sub-graph that is descended from every sensitive vertex included in the screened provenance graph by: (Sekar, paragraph 0271, descendants; paragraph 0086, graph, paragraph 0072, 0345, sub-graph, real-tie detection from which scenario sub-graphs are extracted);
determining, for each edge in the screened provenance graph, whether a child of an edge being processed is a flagged destination within the flagged destination configuration file (Sekar, paragraph 0182, dependency edges, paragraph 0202, flagged address, flagged tag);
determining whether a parent is in any of the taint sets stored in the taint storage if the child is a flagged destination (Sekar, paragraph 0198, edges to be included in final compact scenario representation);
logging an entry in a log file that indicates that there was a sensitive source that was associated with the flagged destination if the parent is in any of the taint sets (Sekar, paragraphs 0078 and 0079., events collected by logging system).
;storing the taint sets of sensitive data to be tracked at the container level within a taint storage (Sekar, paragraphs 0085-0086, storage, audit logs).
Sekar discloses a taint tracking system for providing sensitive dataflow tracking, comprising receive audit records to create a provenance graph of vertices and edges associated with kernel system call events being monitored based on the received audit records; create one or more final taints set of sensitive data to be tracked that includes vertices and edges that are descended from a particular sensitive source using one or more dependency checkers, but does not explicitly disclose a taint tracking system for providing sensitive dataflow tracking for containerized applications, comprising; receive audit records including container information to create a provenance graph of vertices and edges associated with kernel system call events being monitored based on the received audit records; create one or more final taints set of sensitive data to be tracked at a container level that includes vertices and edges that are descended from a particular sensitive source using one or more dependency checkers; use the information in at least one of the created screened provenance graph or the one or more created final taint sets to identify at least one of sensitive data or sensitive data flow paths associated with data related to the kernel system call events that should be tracked.
However, in an analogous art, Yermakov discloses a taint tracking system for providing sensitive dataflow tracking for containerized applications, comprising (Yermakov, paragraph 0035, virtual containers configured to protect resource, tainted data);
receive audit records including container information to create a provenance graph of vertices and edges associated with kernel system call events being monitored based on the received audit records (Yermakov, paragraph 0035, virtual containers configured to protect resource, tainted data);
create one or more final taints set of sensitive data to be tracked at a container level that includes vertices and edges that are descended from a particular sensitive source using one or more dependency checkers (Yermakov, paragraph 0035, virtual containers configured to protect resource, tainted data);
use the information in at least one of the created screened provenance graph or the one or more created final taint sets to identify at least one of sensitive data or sensitive data flow paths associated with data related to the kernel system call events that should be tracked (Yermakov, paragraph 0034, kernel, sensitive information initially tainted by gateway or client device, tainting marked so that it can be tracked, tainted data as sensitive information, paragraph 0035, virtual containers configured to protect resources).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Yermakov with the taint tracking system/ method/ non-transitory computer readable media of Sekar to include a taint tracking system for providing sensitive dataflow tracking for containerized applications, comprising; receive audit records including container information to create a provenance graph of vertices and edges associated with kernel system call events being monitored based on the received audit records; create one or more final taints set of sensitive data to be tracked at a container level that includes vertices and edges that are descended from a particular sensitive source using one or more dependency checkers. One would have been motivated to provide users with the benefits of detecting and blocking transmission of sensitive information using dynamic data tainting (Yermakov: paragraph 0003).
Sekar and Yermakov do not explicitly disclose in response, to cause systems in at least one container network associated with the containerized applications to track at least one of the sensitive data or data through the sensitive data flow paths in the at least one container network.
However, in an analogous art, Gervais discloses in response, to cause systems in at least one container network associated with the containerized applications to track at least one of the sensitive data or data through the sensitive data flow paths in the at least one container network (Gervais, paragraph 0019, network domains, events, paragraph 0036, kernel, event tracking, paragraph 0038, network connection events, agent resides on both source and destination server, tracking is automated; paragraph 0049, containerization systems, cloud information systems, containers virtualize access to resources, encapsulate software into containers; paragraph 0039, kernel based event monitoring).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Gervais with the taint tracking system/ method/ non-transitory computer readable media of Sekar and Yermakov to include in response, to cause systems in at least one container network associated with the containerized applications to track at least one of the sensitive data or data through the sensitive data flow paths in the at least one container network. One would have been motivated to provide users with the benefits of an operating system that identifies insider threats, external attacks, data loss and ensures compliance to a large number of information security and data handling regulations and standards (Gervais: paragraph 0015).
Regarding claim 3, Sekar, Yermakov, and Gervais disclose the taint tracking system of claim 1 Sekar, Yermakov, and Gervais disclose wherein the taint tracking system includes a single audit reporter, a single taint tracking kernel, and a single taint storage. (Sekar, paragraphs 0085-0086, system stores dependencies in a graph data structure, single host, paragraph 0199, results in a compact scenario graph representation, paragraph 0342, track back to root causes of intrusion: paragraph 0068 kernel)
Regarding claim 4,. Sekar and Yermakov disclose the taint tracking system of claim 1. Sekar, Yermakov, and Gervais disclose wherein the taint tracking system is further configured to: processes the sensitivity manifest to produce the storage screen used by the taint tracking kernel to screen the vertices and edges that get stored in the provenance graph. (Sekar, paragraphs 0085-0086, system stores dependencies in a graph data structure, single host, paragraph 0199, results in a compact scenario graph representation, paragraph 0342, track back to root causes of intrusion: paragraph 0068 kernel; paragraph 0072, generating a tagged dependence graph, sensitivity of data, paragraph 0075, provenance graph)
Regarding claim 5, Sekar, Yermakov, and Gervais disclose the taint tracking system of claim 4. Sekar, Yermakov, and Gervais disclose the taint tracking system is further configured to annotate provenance graph vertices and/or edges that are identified as being sensitive. (Sekar, paragraph 0072, tagged dependence graph, tags, sensitivity of data, paragraph 0239, vertex: paragraph 0084, graph edge; paragraph 0147, rule-based notation; paragraph 0202, tag modified)
Regarding claim 7, Sekar, Yermakov, and Gervais disclose the taint tracking system of claim 4. Sekar, Yermakov, and Gervais disclose wherein the storage screen created describes to the taint tracking system where sensitive data is located within a container, which application produces new sensitive data, and from where/which? remote network services data can be imported (Sekar, paragraph 0075, backward analysis, provenance graph).
Regarding claim 11, Sekar discloses a method for providing sensitive dataflow taint tracking, comprising (Sekar, paragraph 0366, computer, methods, computer readable media; paragraph 0387, computing device, paragraph 0073, taint detection checks);
generating one or more synthesized audit records based on received event audit records that includes information associated with each event included in the synthesized audit record (Sekar, paragraph 0069, vertices, edges, graphs, attack detection causality analysis, audit stream)
creating a provenance graph of vertices and edges associated with kernel system call events being monitored based on the one or more synthesized audit records (Sekar, paragraph 0342, tracking, trace back to root causes, logging system; paragraph 0318, kernel updates: paragraph 0129, provenance tags derived from audit history);
creating a screened provenance graph that includes data deemed sensitive by performing a first level of pruning of the provenance graph using one or more storage screens (Sekar, paragraph 0199, graph representation, merging, pruning, writing);
creating one or more final taints set of sensitive data to be tracked, that includes vertices and edges that are descended from a particular sensitive source using one or more dependency checkers (Sekar, paragraph 0072, tags, data provenance from audit logs, flow labels; paragraph 0079, identify sources of the attack);
wherein the one or more dependency checkers are configured to check ancestral lineage of the vertices and edges included in the screened provenance graph and keep track of a sub-graph that is descended from every sensitive vertex included in the screened provenance graph by: (Sekar, paragraph 0271, descendants; paragraph 0086, graph, paragraph 0072, 0345, sub-graph, real-tie detection from which scenario sub-graphs are extracted);
determining, for each edge in the screened provenance graph, whether a child of an edge being processed is a flagged destination within the flagged destination configuration file (Sekar, paragraph 0182, dependency edges, paragraph 0202, flagged address, flagged tag);
determining whether a parent is in any of the taint sets stored in the taint storage if the child is a flagged destination (Sekar, paragraph 0198, edges to be included in final compact scenario representation);
logging an entry in a log file that indicates that there was a sensitive source that was associated with the flagged destination if the parent is in any of the taint sets (Sekar, paragraphs 0078 and 0079., events collected by logging system);
storing the taint sets of sensitive data to be tracked at the container level within a taint storage (Sekar, paragraphs 0085-0086, storage, audit logs).
Sekar discloses a method for providing sensitive dataflow taint tracking; generating one or more synthesized audit records based on received event audit records that includes information associated with each event included in the synthesized audit records; generating one or more synthesized audit records based on received event audit records that includes information associated with each event included in the synthesized audit records; storing the taint sets of sensitive data to be tracked within a taint storage, but does not explicitly disclose a method for providing sensitive dataflow taint tracking for containerized applications, comprising, generating one or more synthesized audit records based on received event audit records that includes container information associated with each event included in the synthesized audit records; generating one or more synthesized audit records based on received event audit records that includes container information associated with each event included in the synthesized audit records; use the information in at least one of the created screened provenance graph or the one or more created final taint sets to identify at least one of sensitive data or sensitive data flow paths associated with data related to the kernel system call events that should be tracked.
However, in an analogous art, Yermakov discloses a method for providing sensitive dataflow taint tracking for containerized applications, comprising (Yermakov, paragraph 0035, virtual containers configured to protect resource, tainted data);
generating one or more synthesized audit records based on received event audit records that includes container information associated with each event included in the synthesized audit records (Yermakov, paragraph 0035, virtual containers configured to protect resource, tainted data);
generating one or more synthesized audit records based on received event audit records that includes container information associated with each event included in the synthesized audit records (Yermakov, paragraph 0035, virtual containers configured to protect resource, tainted data);
storing the taint sets of sensitive data to be tracked at the container level within a taint storage (Yermakov, paragraph 0035, virtual containers configured to protect resource, tainted data);
use the information in at least one of the created screened provenance graph or the one or more created final taint sets to identify at least one of sensitive data or sensitive data flow paths associated with data related to the kernel system call events that should be tracked (Yermakov, paragraph 0034, kernel, sensitive information initially tainted by gateway or client device, tainting marked so that it can be tracked, tainted data as sensitive information, paragraph 0035, virtual containers configured to protect resources).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Yermakov with the taint tracking system/ method/ non-transitory computer readable media of Sekar to include a method for providing sensitive dataflow taint tracking for containerized applications, comprising, generating one or more synthesized audit records based on received event audit records that includes container information associated with each event included in the synthesized audit records; generating one or more synthesized audit records based on received event audit records that includes container information associated with each event included in the synthesized audit records; storing the taint sets of sensitive data to be tracked at the container level within a taint storage. One would have been motivated to provide users with the benefits of detecting and blocking transmission of sensitive information using dynamic data tainting (Yermakov: paragraph 0003).
Sekar and Yermakov do not explicitly disclose in response, to cause systems in at least one container network associated with the containerized applications to track at least one of the sensitive data or data through the sensitive data flow paths in the at least one container network.
However, in an analogous art, Gervais discloses in response, to cause systems in at least one container network associated with the containerized applications to track at least one of the sensitive data or data through the sensitive data flow paths in the at least one container network (Gervais, paragraph 0019, network domains, events, paragraph 0036, kernel, event tracking, paragraph 0038, network connection events, agent resides on both source and destination server, tracking is automated; paragraph 0049, containerization systems, cloud information systems, containers virtualize access to resources, encapsulate software into containers; paragraph 0039, kernel based event monitoring).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Gervais with the taint tracking system/ method/ non-transitory computer readable media of Sekar and Yermakov to include in response, to cause systems in at least one container network associated with the containerized applications to track at least one of the sensitive data or data through the sensitive data flow paths in the at least one container network. One would have been motivated to provide users with the benefits of an operating system that identifies insider threats, external attacks, data loss and ensures compliance to a large number of information security and data handling regulations and standards (Gervais: paragraph 0015).
Regarding claim 12, Sekar, Yermakov, and Gervais disclose the method of claim 11
Sekar, Yermakov, and Gervais disclose wherein the storage screen is by a sensitivity manifest ingester based on a sensitivity manifest that is input into the sensitivity manifest ingester to produce the storage screen used to screen the vertices and edges that get stored in the provenance graph. (Sekar, paragraphs 0085-0086, system stores dependencies in a graph data structure, single host, paragraph 0199, results in a compact scenario graph representation, paragraph 0342, track back to root causes of intrusion: paragraph 0068 kernel; paragraph 0072, generating a tagged dependence graph, sensitivity of data, paragraph 0075, provenance graph)
Regarding claim 13, Sekar, Yermakov, and Gervais disclose the method of claim 12.
Sekar, Yermakov, and Gervais disclose wherein the sensitivity manifest includes annotated provenance graph vertices and/or edges that should be considered sensitive. (Sekar, paragraph 0072, tagged dependence graph, tags, sensitivity of data, paragraph 0239, vertex: paragraph 0084, graph edge; paragraph 0147, rule-based notation; paragraph 0202, tag modified)
Regarding claim 14, Sekar, Yermakov, and Gervais disclose the method of claim 11
Sekar, Yermakov, and Gervais disclose wherein creating one or more final taints set of sensitive data to be tracked at a container level using the dependency checker comprises:
checking ancestral lineage of the vertices and edges included in the screened provenance graph; (Sekar, paragraph 0271, 0345, output simplification, real-tie detection from which scenario sub-graphs are extracted)
tracking a sub-graph that is descended from every sensitive vertex included in the screened provenance graph. (Sekar, paragraph 0072, 0345, sub-graph, real-tie detection from which scenario sub-graphs are extracted)
Regarding claim 16, Sekar discloses one or more non-transitory computer readable media having instructions stored thereon which, when executed by one or more processors, cause the one or more processors to perform operations comprising (Sekar, paragraph 0366, computer, methods, computer readable media; paragraph 0387, computing device, paragraph 0073, taint detection checks);
generating one or more synthesized audit records based on received event audit records that includes information associated with each event included in the synthesized audit records; (Sekar, paragraph 0069, vertices, edges, graphs, attack detection causality analysis, audit stream);
creating a provenance graph of vertices and edges associated with kernel system call events being monitored based on the one or more synthesized audit records; (Sekar, paragraph 0342, tracking, trace back to root causes, logging system; paragraph 0318, kernel updates: paragraph 0129, provenance tags derived from audit history)
creating a screened provenance graph that includes data deemed sensitive by performing a first level of pruning of the provenance graph using one or more storage screens; (Sekar, paragraph 0199, graph representation, merging, pruning, writing)
creating one or more final taints set of sensitive data to be tracked, that includes vertices and edges that are descended from a particular sensitive source using one or more dependency checkers; and (Sekar, paragraph 0072, tags, data provenance from audit logs, flow labels; paragraph 0079, identify sources of the attack);
wherein the one or more dependency checkers are configured to check ancestral lineage of the vertices and edges included in the screened provenance graph and keep track of a sub-graph that is descended from every sensitive vertex included in the screened provenance graph by: (Sekar, paragraph 0271, descendants; paragraph 0086, graph, paragraph 0072, 0345, sub-graph, real-tie detection from which scenario sub-graphs are extracted);
determining, for each edge in the screened provenance graph, whether a child of an edge being processed is a flagged destination within the flagged destination configuration file (Sekar, paragraph 0182, dependency edges, paragraph 0202, flagged address, flagged tag);
determining whether a parent is in any of the taint sets stored in the taint storage if the child is a flagged destination (Sekar, paragraph 0198, edges to be included in final compact scenario representation);
logging an entry in a log file that indicates that there was a sensitive source that was associated with the flagged destination if the parent is in any of the taint sets (Sekar, paragraphs 0078 and 0079., events collected by logging system);
storing the taint sets of sensitive data to be tracked at the container level within a taint storage (Sekar, paragraphs 0085-0086, storage, audit logs).
Sekar discloses generating one or more synthesized audit records based on received event audit records that includes information associated with each event included in the synthesized audit records; creating one or more final taints set of sensitive data to be tracked, that includes vertices and edges that are descended from a particular sensitive source using one or more dependency checkers; and storing the taint sets of sensitive data to be tracked within a taint storage, but does not disclose generating one or more synthesized audit records based on received event audit records that includes container information associated with each event included in the synthesized audit records; creating one or more final taints set of sensitive data to be tracked at a container level, that includes vertices and edges that are descended from a particular sensitive source using one or more dependency checkers; use the information in at least one of the created screened provenance graph or the one or more created final taint sets to identify at least one of sensitive data or sensitive data flow paths associated with data related to the kernel system call events that should be tracked..
However, in an analogous art, Yermakov discloses generating one or more synthesized audit records based on received event audit records that includes container information associated with each event included in the synthesized audit records (Yermakov, paragraph 0035, virtual containers configured to protect resource, tainted data);
creating one or more final taints set of sensitive data to be tracked at a container level, that includes vertices and edges that are descended from a particular sensitive source using one or more dependency checkers (Yermakov, paragraph 0035, virtual containers configured to protect resource, tainted data);
storing the taint sets of sensitive data to be tracked at the container level within a taint storage (Yermakov, paragraph 0035, virtual containers configured to protect resource, tainted data);
use the information in at least one of the created screened provenance graph or the one or more created final taint sets to identify at least one of sensitive data or sensitive data flow paths associated with data related to the kernel system call events that should be tracked (Yermakov, paragraph 0034, kernel, sensitive information initially tainted by gateway or client device, tainting marked so that it can be tracked, tainted data as sensitive information, paragraph 0035, virtual containers configured to protect resources)..
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Yermakov with the taint tracking system/ method/ non-transitory computer readable media of Sekar to include generating one or more synthesized audit records based on received event audit records that includes container information associated with each event included in the synthesized audit records; creating one or more final taints set of sensitive data to be tracked at a container level, that includes vertices and edges that are descended from a particular sensitive source using one or more dependency checkers; and storing the taint sets of sensitive data to be tracked at the container level within a taint storage One would have been motivated to provide users with the benefits of detecting and blocking transmission of sensitive information using dynamic data tainting (Yermakov: paragraph 0003).
Sekar and Yermakov do not explicitly disclose in response, to cause systems in at least one container network associated with the containerized applications to track at least one of the sensitive data or data through the sensitive data flow paths in the at least one container network.
However, in an analogous art, Gervais discloses in response, to cause systems in at least one container network associated with the containerized applications to track at least one of the sensitive data or data through the sensitive data flow paths in the at least one container network (Gervais, paragraph 0019, network domains, events, paragraph 0036, kernel, event tracking, paragraph 0038, network connection events, agent resides on both source and destination server, tracking is automated; paragraph 0049, containerization systems, cloud information systems, containers virtualize access to resources, encapsulate software into containers; paragraph 0039, kernel based event monitoring).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Gervais with the taint tracking system/ method/ non-transitory computer readable media of Sekar and Yermakov to include in response, to cause systems in at least one container network associated with the containerized applications to track at least one of the sensitive data or data through the sensitive data flow paths in the at least one container network. One would have been motivated to provide users with the benefits of an operating system that identifies insider threats, external attacks, data loss and ensures compliance to a large number of information security and data handling regulations and standards (Gervais: paragraph 0015).
Regarding claim 18, Sekar discloses a method of providing sensitive dataflow policy violations, comprising (Sekar, paragraph 0366, computer, methods, computer readable media; paragraph 0387, computing device, paragraph 0073, taint detection checks);
deploying one or more networked taint tracking systems on a network in accordance with the system of claim 1; (Sekar, paragraph 0065, implement attack detection, provenance, paragraph 0072l provenance, taint tags);
detecting, by the networked taint tracking systems, sensitive data requiring taint tracking based on analysis of received event audit records in accordance with the system of claim 1; (Sekar, paragraphs 0121-0123, audit data, detection, sensitive; paragraph 0184, sensitive information);
generating, by the one or more networked taint tracking systems, taints sets that include sensitive data being monitored and result in the tracking of sensitive dataflow policy violation alerts; and (Sekar, paragraph 0072, tags, data provenance from audit logs, flow labels; paragraph 0079, identify sources of the attack);
storing the taint sets of sensitive data being monitored within a taint storage. (Sekar, paragraphs 0085-0086, storage, audit logs).
Sekar discloses storing the taint sets of sensitive data being monitored within a taint storage, but do not explicitly disclose storing the taint sets of sensitive data being monitored at the container level within a taint storage.
However, in an analogous art, Yermakov discloses storing the taint sets of sensitive data being monitored at the container level within a taint storage (Yermakov, paragraph 0035, virtual containers configured to protect resources).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Yermakov with the taint tracking system/ method/ non-transitory computer readable media of Sekar to include storing the taint sets of sensitive data being monitored within a taint storage, but do not explicitly disclose storing the taint sets of sensitive data being monitored at the container level within a taint storage One would have been motivated to provide users with the benefits of detecting and blocking transmission of sensitive information using dynamic data tainting (Yermakov: paragraph 0003).
Regarding claim 19, Sekar, Yermakov, and Gervais disclose the method of claim 18.
Sekar, Yermakov, and Gervais disclose wherein generating the taints sets that include sensitive data being monitored includes using a storage screen based on a sensitivity manifest as input to screen the vertices and edges that get stored in a provenance graph and result in the tracking of sensitive dataflow policy violation alerts (Sekar, paragraph 0072, tags, data provenance from audit logs, flow labels; paragraph 0079, identify sources of the attack).
Regarding claim 20, Sekar, Yermakov, and Gervais disclose the method of claim 18.
Sekar, Yermakov, and Gervais disclose wherein generating the taints sets that include sensitive data being monitored includes using a dependency checker and a set of flagged destinations as input to the dependency checker to screen the vertices and edges that get stored in a provenance graph and result in the tracking of sensitive dataflow policy violation alerts (Sekar, paragraph 0171l trustworthiness flag, paragraph 0123, untrusted sources, paragraph 0137, detector flag; paragraph 0146, edges; paragraph 0239, suspect vertex).
Claim 2 is rejected under 35 U.S.C. 103 as being unpatentable over Sekar (US20200059481) filed August 19, 2019, in view of Yermakov (US20110307951), filed June 9,2011, and Gervais (US20180176244), filed December 19, 2017, and further in view of Johns (US20170318045), filed April 27, 2016.
Regarding claim 2, Sekar, Yermakov, and Gervais disclose the taint tracking system of claim 1.
Sekar, Yermakov, and Gervais do not explicitly disclose wherein the taint tracking system is further configured to: a bridge translator configured to generate one or more synthesized audit records that includes container information associated with each event based on one or more received event audit records.
However, in an analogous art, Johns discloses wherein the taint tracking system is further configured to: a bridge translator configured to generate one or more synthesized audit records that includes container information associated with each event based on one or more received event audit records (Johns, paragraph 0054, complementary taint engines can be configured at each end of a transport link between client and server, transport link across two environments)
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Johns with the taint tracking system/ method/ non-transitory computer readable media of Sekar, Yermakov, and Gervais to include wherein the taint tracking system is further configured to: a bridge translator configured to generate one or more synthesized audit records that includes container information associated with each event based on one or more received event audit records One would have been motivated to provide users with the benefits of detecting vulnerabilities in web applications (Johns: paragraph 0001).
Claim 10 is rejected under 35 U.S.C. 103 as being unpatentable over Sekar (US20200059481) filed August 19, 2019, in view of Yermakov (US20110307951), filed June 9,2011, and Gervais (US20180176244), filed December 19, 2017, and further in view of Chari (US20190121979), filed October 19, 2017.
Regarding claim 10, Sekar, Yermakov, and Gervais disclose the taint tracking system of claim 1.
Sekar, Yermakov, and Gervais disclose one or more network-tagged provenance coordination (NTPC) systems (Sekar, paragraph 0072, tag based identifying subjects objects and events, data provenance).
Sekar, Yermakov, and Gervais do not explicitly disclose a network tagged specification file that includes a list of all the vertices that are deemed sensitive and therefore should be tracked, wherein the one or more NTPC systems are configured to include labels to any network packets that meets criteria defined in a network tagged specification file.
However, Chari discloses a network tagged specification file that includes a list of all the vertices that are deemed sensitive and therefore should be tracked, wherein the one or more NTPC systems are configured to include labels to any network packets that meets criteria defined in a network tagged specification file (Chari, paragraph 0053, packet capture appliance, forensics dashboard, incident investigations; 0059, analysing, managing, monitoring, reporting security events).
Therefore, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention to combine the teachings of Chari with the taint tracking system/ method/ non-transitory computer readable media of Sekar, Yermakov, and Gervais to include a network tagged specification file that includes a list of all the vertices that are deemed sensitive and therefore should be tracked, wherein the one or more NTPC systems are configured to include labels to any network packets that meets criteria defined in a network tagged specification files One would have been motivated to provide users with the benefits of determining anomalous behavior in an application program (Chari: paragraph 0001).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to WALTER J MALINOWSKI whose telephone number is (571)272-5368. The examiner can normally be reached 8-6:30 MTWH.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, LUU PHAM can be reached at 5712705002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/W.J.M/Examiner, Art Unit 2439
/LUU T PHAM/Supervisory Patent Examiner, Art Unit 2439