Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
Response to Amendment
Claims 1, 4, 7, 9, 12-13 and 17 have been amended.
Claims 1-20 are pending.
Response to Arguments
Applicant's arguments filed 6/15/2026 have been fully considered but they are not persuasive. The prior art citations for the rejected limitations have been updated with respect to the amended claim language.
CLAIM REJECTIONS - 35 USC § 103
II. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
III. CLAIMS 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over COFFEY et al (USPN 11,171,980) in view of LAWSON (USPN 11,985,142) and XIE et al “Using Bayesian Networks for Cyber Security Analysis”.
a. Per claim 1, COFFEY et al teach a method comprising:
performing a risk evaluation via a risk management security platform (RMSP), including (col.8 line 43-col.9 line 2, col.10 line 23-col.11 line 3—risk management service and security analytics system that performs risk assessment operations):
receiving activity data for a risk-oriented event corresponding to a user participant (col.10 lines 4-22, col.10 line 52-col.11 line 31, col.24 line 52-col.26 line 29—receiving user behavior and interaction, mouse activity and web browsing activity data for risk analytics);
generating an insight as an output providing an evaluation of risk for the user participant in a risk category based on the activity data (Figure 8 steps 803-804, col.13 line 55-col.14 line 41, col.25 line 47-col.26 line 16, col.26 lines 30-65, col.29 line 66-col.30 line 39—evaluating risk for the user as anomalous, abnormal, unexpected or malicious based on the activity data; evaluating the electronic data and communications inputs for purposes of identifying high risk behavior by a user, performing an event risk analysis on events performed by an entity to assign corresponding risk scores);
generating a risk score for the user participant based on the insight (Figure 8 step 805, col.30 lines 40-52—assigning risk scores based on risk analytics service associated with user’s behavior); and
providing a notification based on the risk score (Figure 8 step 806, col.29 lines 3-52, col.30 line 53-col.31 line 7—propagating user’s risk scores to other users serves as a notice).
COFFEY et al teach the limitations, as applied above, risk assessments that automatically provision auto-prevention policies enforcement tools, propagating user’s risk scores to other users (col.29 lines 3-52) and assigning risk scores based on risk analytics service associated with user’s behavior (col.17 line 1-col.18 line 18, col.26 line 30-col.27 line 15) , yet fail to explicitly teach “generating a risk score for the user participant based on the insight via a causal belief network (CBN), wherein the CBN comprises: wherein the CBN comprises: a plurality of input nodes corresponding to the activity data, a plurality of internal nodes configured to generate the insight based on causal relationships with the input nodes, and an output node configured to generate the risk score based on causal relationships with the plurality of internal nodes”.
However, LAWSON using a Bayesian probabilistic analysis and framework for anomaly detection and cybersecurity analysis using input from raw sources of data, external and internal sources; performing analysis of internal and external data including readout from machine learning models; learning the normal ‘pattern of life’ for internal and external address identities in connection with the rest of the network and training the model from devices, users, behavior and activities, network flow traffic, outputs from one or more cyber security analysis tools analyzing the system, etc. (col.5 lines 57-64, col.7 lines 21-36, col.10 lines 30-47, col.12 line 50-col.13 line 35). The Bayesian probabilistic analysis provisioned in LAWSON teaches generating anomaly scores and threat values using Bayesian probabilistic analysis and discovery of true associations between different network components for modeling (col.16 lines 20-29 and 34-42, col.17 line 50-col.18 line 15), generating notifications and alerts based on the anomaly score (col.10 lines 30-67) and using Bayesian probabilistic analysis to identify meaningful relationships within data and quantifying the associated uncertainty by employing probabilistic scoring related to malign categories (col.27 lines 33-65). LAWSON further teaches using an intelligent-adversary simulator cooperating with a network module and network probes ingesting traffic data for network devices and network users in the network under analysis with machine learning models trained on a normal behavior of users, devices, peers, relationships among entities, and interactions between them, on a network to factor this network analysis into determining the threat risk parameter and analyzing behavior in the context of other similar network devices (col.5 lines 52-56, col.8 lines 12-24, col.17 lines 1-31). A Bayesian Network (also known as a Bayes network, belief network, or decision network) is a probabilistic graphical model that represents a set of variables and their conditional dependencies via a directed acyclic graph (DAG). This model is used for representing and solving problems that involve uncertainty and probabilistic events, which qualifies as a causal belief network.
XIE et al teach the use of a causal belief network (i.e, a Bayesian network) for cyber security analysis. In particular, XIE et al (see the bridging paragraph of the left and right column, on page 212) describes that a “Bayesian network (BN) is a graphical representation of cause-and-effect relationships within a problem domain. More formally, a Bayesian network is a Directed Acyclic Graph (DAG) in which: the nodes represent variables of interest (propositions); the directed links represent the causal influence among the variables”. XIE et al describe a BN-based tool to measure network security risk (see section 3, on pages 216-217).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed the invention to combine the teachings of COFFEY et al with LAWSON and XIE et al for the purpose of provisioning: notifications/alerts based on the risk/threat or scores via a Bayesian probabilistic framework that correlates causal links, wherein Bayesian networks are well-known in the art to model probabilities for risk analysis from activity data of a plurality of input devices, probes, internal and external sources related to the activity data in order to analyze and output data based on causal relationships with the input devices and peer associations.
Furthermore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to use a causal belief network (i.e., a Bayesian network) to determine network security risk as in XIE et al in the invention of COFFEY et al because the experimental results of XIE et al “show that using Bayesian networks may bring in new opportunities for improved enterprise security analysis” (see the last paragraph in section 6, on page 220), that “[o]ur work makes use of the output of intrusion detectors and incorporates it into a holistic security analysis framework” and that “[o]ur BN model address a wider range of security analysis, most importantly the problem of real-time situation awareness” (see the first and second paragraphs of section 5).
Claims 9 and 17 contain limitations that are substantially equivalent to the limitations of claim 1, and are therefore rejected under same basis. As per claim 9, it is rejected for similar reasons as given for claim 1. COFFEY et al further teach an apparatus (information handling system 100, at Figure 1, and col.3 lines 13-15, which describes that “FIG. 1 is a generalized illustration of an information handling system that can be used to implement selected embodiments of the present disclosure”) comprising: a processor (CPU 102, at figure 1, and col.3 lines 16-17) configured to implement a risk management security platform to perform a risk evaluation (see col.3 lines 34-51, which describes that “[i]n various embodiments, the contagion risk analysis system 118 performs a contagion-based risk analysis operation). As per claim 17, COFFEY et al further teach a memory device storing instructions, that when executed, cause a processor (see col.32, lines 8-37, which describes that “[e]mbodiments of the invention are described with reference to flowchart illustrations and/or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the invention). It will be understood that each block of the flowchart illustrations and/or block diagrams, and combinations of blocks in the flowchart illustrations and/or block diagrams, can be implemented by computer program instructions.
b. Per claim 2, COFFEY et al with LAWSON and XIE et al teach the method of claim 1, LAWSON further teaches the risk evaluation further including: grouping a plurality of user participants having a shared attribute into a segment; evaluating a risk trend for the segment based on the risk score for the plurality of user participants; and generating the notification regarding the risk trend for the segment (col.7 lines 61-67, col.9 line 64-col.10 line 6, col.10 lines 30-67, col.11 lines 15-22—identifying key patterns and trends in the data, evaluating and analyzing metrics to combine with patterns of behavior and life data, combining sets of metrics based on anomaly scores and threat alerts).
Claims 10 and 19 contain limitations that are substantially equivalent to the limitations of claim 2, and are therefore rejected under same basis.
c. Per claim 3, COFFEY et al with LAWSON and XIE et al teach the method of claim 1, COFFEY et al further teach the risk evaluation further including: generating the risk score based on a probabilistic graphical model (col.14 lines 34-49, col.15 lines 22-43, col.15 line 56-col.16 line 67, col.17 lines 20-55—risk score and probability distribution function and temporal models for quantifying risk assessment; LAWSON: col.8 lines 50-63, col.12 line 50-col.13 line 19—Bayesian probabilistic analysis modeling, Bayesian network (BN) is a graphical representation of cause-and-effect relationships within a problem domain, graphically rendering anomaly scores).
d. Per claim 4, COFFEY et al with LAWSON and XIE et al teach the method of claim 3, LAWSON further teaches the method further comprising: wherein the insight comprises a human-parsable explanation identifying at least one causal factor contributing to the risk score (col.5 line 57-col.6 line 64, col.7 lines 1-45—gathering data and feedback to form hypothesis that either support or refute the potential threat or suspicious activity; col.8 lines 25-49, col.9 lines 15-28—correlating causal links between activities to supply this input into the cyber-threat module, which can also factor this network activity link to a particular email causal link analysis into its determination of the threat risk parameter; cyber threat defense system monitoring email activity and network activity to feed this data to correlate causal links between these activities to supply this input into the cyber threat analysis; col.23 line 50-col.24 line 32—enabling the output of a prediction about the category of an email being analyzed using a learned hypothesis and including focused response actions selectable through the user interface; col.27 lines 12-24—utilizing human operator to for confirmation response).
Claim 12 contains limitations that are substantially equivalent to the limitations of claim 4, and are therefore rejected under same basis.
e. Per claim 5, COFFEY et al with LAWSON and XIE et al teach the method of claim 4, LAWSON further teaches the method further comprising: modeling the plurality of internal nodes and the output node based on conditional probability tables, with a conditional probability table defining a probability of a value for a corresponding node based on values from parent nodes that provide causal input to the corresponding node (col.7 lines 28-36, col.9 lines 39-44—assigning probability of a given cyber threat hypothesis including abnormal behavior or suspicious activity, modeling including threat risk parameter score or probability indicative of the threat level; col.12 lines 50-61, col.16 lines 34-42—Bayesian mathematical model and probabilistic approach for detecting behavioral change in computers).
Claims 13 and 18 contain limitations that are substantially equivalent to the limitations of claim 5, and are therefore rejected under same basis.
f. Per claim 6, COFFEY et al with LAWSON and XIE et al teach the method of claim 4, LAWSON further teaches the method further comprising: modeling the CBN to include: a first input node representing the activity data for the user participant; and a second input node representing a risk modifier value for the user participant, wherein certain values for the second input node amplify a risk associated with the first input node (col.7 lines 28-36, col.9 lines 39-44—assigning probability of a given cyber threat hypothesis including abnormal behavior or suspicious activity, modeling including threat risk parameter score or probability indicative of the threat level; col.12 lines 50-61, col.16 lines 34-42—Bayesian mathematical model and probabilistic approach for detecting behavioral change in computers; col.23 lines 41-49—using a k-mean s model applied to a modified term frequency).
g. Per claim 7, COFFEY et al with LAWSON and XIE et al teach the method of claim 4, LAWSON further teaches the method wherein: each of the plurality of internal nodes corresponds to a respective risk category and generates a respective insight explaining a contribution of the activity data to the risk score; and the output node aggregates outputs of the plurality of internal nodes to generate the risk score representing an aggregate risk across a plurality of risk categories (col.2 lines 11-67, col.10 lines 48-58, col.23 lines 50-59—classifying and categorizing of threat risk for determining score, metrics are combined and passed through machine learning algorithms to produce a single anomaly score; col.18 line 64-col.20 line 29—Likely Recipient Classifier wherein given recipient may be considered to be a label/class/category identifying the outbound emails that are sent to that recipient email address, plurality of metrics/characteristics may be extracted from each email, the rarer the characteristics are, then the more weight is given to those specific characteristics as key indicators, considering each of these known recipients in turn and determining a score associated with the probability of a match between the characteristics extracted from the draft email and the key identifiers for each known recipient, the Likely Recipient Classifier may determine the known recipient with the highest probability of a match for the draft email, who may be referred to as the expected recipient).
h. Per claim 8, COFFEY et al with LAWSON and XIE et al teach the method of claim 1, LAWSON further teaches the risk evaluation further including: implementing an action plan to reduce risk, including: identifying activity data having a value that corresponds to elevated risk; accessing a data structure of remedial actions based on a type of the activity data; and implementing a remedial action associated with the type of the activity data (col.3 lines 1-20, col.7 lines 61-67, col.8 line 33-col.9 line 14, col.9 lines 39-44, col.24 line 45-col.25 line 61—determining categories and types of cyber threats, threat levels, threshold exceeded event and appropriate response actions, autonomous action and response module implements actions to reduce risks; COFFEY et al: col.29 lines 3-52—automatically provision auto-prevention policies enforcement tools).
Claims 16 and 20 contain limitations that are substantially equivalent to the limitations of claim 8, and are therefore rejected under same basis.
i. Per claim 11, COFFEY et al with LAWSON and XIE et al teach the apparatus of claim 9, LAWSON further teaches comprising the processor further configured to: implement an integration service to gather and normal the activity data, including: obtain the activity data from a plurality of third-party sources via application program interface (API) calls; and convert the activity data from source formats corresponding to each of the plurality of third-party sources into a standard format; and store the activity data in the standard format to a data structure (col.6 lines 54-59, col.12 lines 10-17, col.25 lines 3-19—Open Source APIs, conversion of data into a safe format and storage).
j. Per claim 14, COFFEY et al with LAWSON and XIE et al teach the apparatus of claim 10, LAWSON further teaches comprising the processor further configured to: implement a notification service to provide the notification, including: determine to provide a notification based on the risk score; generate a human-parsable notification message based on the risk score; and select a notification medium from a plurality of notification mediums by which to provide the notification (col.10 lines 30-67, col.26 lines 35-44—generating notifications and alerts based on the anomaly score, types of notifications triggered by anomalies).
k. Per claim 15, COFFEY et al with LAWSON and XIE et al teach the apparatus of claim 10, LAWSON further teaches comprising the processor further configured to: receive a user request for information via a web application; and provide information regarding the insight via the web application (col.28 lines 46-60—receiving client request via web browser based applications; COFFEY et al—col.9 line 16-col.10 line 37, col.10 line 53-col.11 line 3, col.26 lines 52-65—user behavior information associated with user request).
Conclusion
IV. The prior art made of record and not relied upon is considered pertinent to applicant's disclosure: US 20240163312, US 2017/0359220.
V. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
VI. Any inquiry concerning this communication or earlier communications from the examiner should be directed to KRISTIE D SHINGLES whose telephone number is (571)272-3888. The examiner can normally be reached on Monday-Thursday 10am-7pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kamal Divecha can be reached on 571-272-5863. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/KRISTIE D SHINGLES/
Primary Examiner, Art Unit 2453