DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim status in the amendment received on 3/16/2026:
Claims 1, 3 and 7 have been amended.
Claims 19-21 have been canceled.
New claims 22-23 have been added.
Claims 1-18 and 22-23 are pending.
Response to Amendments
Applicant’s amendments have been considered and in response to the amendments:
The previous claim objections have been withdrawn.
Response to Arguments
Applicant’s arguments have been considered but are moot because the arguments do not apply to any of the references being used in the current rejection.
With respect to arguments related to claim 13, the arguments have been considered but they are not persuasive.
In response to applicant's argument that Edwards is nonanalogous art and thus not combinable, it has been held that a prior art reference must either be in the field of the inventor’s endeavor or, if not, then be reasonably pertinent to the particular problem with which the inventor was concerned, in order to be relied upon as a basis for rejection of the claimed invention. See In re Oetiker, 977 F.2d 1443, 24 USPQ2d 1443 (Fed. Cir. 1992).
In this case, the particular problem is evaluating contents according to calculated score. Even if Bulusu uses the results of the evaluation to perform different tasks, such as presenting relevant contents to users, this does not necessarily mean that the process of evaluation per se (as taught by Bulusu) cannot be incorporated into determining relevant documents received from different sources (taught by Edwards) as the particular problem of both references is determining relevancy of contents.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 7-8 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
As to claims 7-8, the claims recite the limitation “the application of probabilistic heuristics”. There is insufficient antecedent basis for the limitation in the claim.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1-3, 6-9 and 22-23 is/are rejected under 35 U.S.C. 103 as being unpatentable over Edwards et al. (Pub. No.: US 20020038430 A1) in view of Martin et al. (Pub. No.: US 20180004942 A1).
As to claim 1, Edwards teaches a computer network security threat monitoring method for a processor and a storage device including instructions configured to run on the processor, including:
continuously gathering machine-readable documents from one or more streams of third-party machine-readable documents from network sources selected based on predetermined selection criteria (paragraph [0012], “the data collection step 104”),
evaluating machine-readable documents gathered from the one or more streams according to one or more productivity rejection criteria and rejecting machine-readable documents that meet the one or more productivity rejection criteria (paragraph [0014], “a set of retention criteria” teaches productivity rejection criteria), and
continuously processing the gathered machine-readable documents to extract threat information about conditions on a network except if they meet the one or more productivity rejection criteria (paragraphs [0033]-[0036], at least “hardware affected” teaches extracted threat information about conditions on a network and paragraph [0019]), and processing the extracted information from different ones of the processed machine-readable documents from the network sources to reveal a threat on the network (paragraphs [0018]-[0019], “…cyber-threat information that is delivered to clients subscribing to the service…”).
Edward does not explicitly teach detecting pattern in the extracted information.
However, in the same field of endeavor (document processing for network security) Martin teaches detecting at least one pattern in an extracted information from different ones of a processed machine-readable documents from network sources to reveal a threat on a network (paragraph [0022], “…If the system detects a minimum number of elements in the network event buffer that match IOC values of a particular threat intelligence in the threat corpus or if the system matches a pattern of elements in the network event buffer to a pattern of IOC values of a particular threat intelligence in the threat corpus…”).
Based on Edwards in view of Martin, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention, to incorporate detecting pattern in the extracted information (taught by Martin) with document collection and analysis (taught by Edward) in order to accurately detect previously and newly identified security threat in the network as motivated by Martin (paragraph [0017]).
As to claim 2, Edwards teaches evaluating machine-readable documents gathered from the streams according to one or more productivity acceptance criteria and wherein the processing the gathered machine-readable documents processes all of the gathered machine-readable documents that satisfy the acceptance criteria to extract threat information (paragraph [0014], “…Intelligence data that satisfies the retention criteria is further assessed at step 308…”).
As to claim 3, Edwards teaches queuing at least some of the documents that do not satisfy the one or more productivity rejection criteria for manual review (paragraph [0006], “The intelligence data is stored in a first data store, and further sent to one or several queues based on the content of the data. Data analysts then review the items specific to their queue and retain or discard the content”).
As to claim 6, Edwards teaches wherein the evaluating documents according to rejection criteria applies a plurality of heuristics (paragraph [0014], “…the criteria includes the number of keyword hits on a source, a date/time stamp for recognizing the same data content and source already retained by the system, and a relevancy ranking on keyword hits to retain only the most relevant intelligence data reporting on the same issue…”).
As to claim 7, Edwards teaches wherein the evaluating documents according to rejection criteria includes the application of probabilistic heuristics (paragraph [0014], “…the criteria includes the number of keyword hits on a source, a date/time stamp for recognizing the same data content and source already retained by the system, and a relevancy ranking on keyword hits to retain only the most relevant intelligence data reporting on the same issue…”).
As to claim 8, Edwards teaches wherein the application of probabilistic heuristics includes calculating a distance between a feature representation of a stream of machine-readable documents and identified clusters previously learned by a probabilistic model (paragraph [0014], “…the criteria includes the number of keyword hits on a source, a date/time stamp for recognizing the same data content and source already retained by the system, and a relevancy ranking on keyword hits to retain only the most relevant intelligence data reporting on the same issue…”).
As to claim 9, Edwards teaches wherein the evaluating documents according to rejection criteria applies deterministic heuristics (paragraph [0014], “…the criteria includes the number of keyword hits on a source, a date/time stamp for recognizing the same data content and source already retained by the system, and a relevancy ranking on keyword hits to retain only the most relevant intelligence data reporting on the same issue…”).
As to claim 22, Martin further teaches wherein the detecting includes correlating co- occurring information from different ones of the sources to reveal threats on the network (paragraph [0073], “…if the IDSs and/or IPSs detect correlations between new network events and threat elements of a newly-identified security threat, the system can merge micro alerts output by the IDSs and/or IPSs with correlations (e.g., matches, temporal pattern matches) between network events in the network accounting log and threat elements in the new threat intelligence in order to calculate a confidence score for exposure to the newly-identified security threat based on both new and past network events…”). The limitations of claim 22 are rejected in view of the analysis of claim 1 above, and the rationale to combine, as discussed in claim 1, applies here as well.
As to claim 23, Martin further teaches continuous extraction is performed by an automated predictive scoring system (paragraph [0073], “…system can then calculate a confidence score for risk of the newly-identified security threat to the network in Block S140 and output an alert accordingly in Block S150 …”). The limitations of claim 23 are rejected in view of the analysis of claim 1 above, and the rationale to combine, as discussed in claim 1, applies here as well.
Claim(s) 4-5 is/are rejected under 35 U.S.C. 103 as being unpatentable over Edwards et al. (Pub. No.: US 20020038430 A1) in view of Martin et al. (Pub. No.: US 20180004942 A1) and further in view of Carr (Patent. No.: US 10353940 B1).
As to claim 4, Edward in view of Martin does not explicitly teach adjusting rejection criteria based on manual review.
However, in the same field of endeavor (document processing) Carr teaches including adjusting at least some of the rejection criteria based on results of the manual review (col. 14, lines 15-36, “The review (e.g. 1 or 0) may be stored with the reviewed document in the training documents buffer 202 as a flag, to indicate that the particular reviewed document is relevant (1) or not relevant (0). In some embodiments, documents that the user considers to be relevant and documents the user considers to be non-relevant are both added to the training buffer 206”).
Based on Edwards in view of Martin and further in view of Carr, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention, to incorporate adjusting document rejection criteria based on manual review (taught by Carr) with detecting pattern in the extracted information (taught by Martin) with document collection and analysis (taught by Edward) in order to accurately detect previously and newly identified security threat in the network as motivated by Martin (paragraph [0017]), and in order to enhance the process of document collection by allowing the user to validate the collected document as motivated by Carr (col. 14, lines 15-36).
As to claim 5, Carr further teaches including confirming at least some of the rejection criteria based on results of the manual review (col. 14, lines 15-36, “The review (e.g. 1 or 0) may be stored with the reviewed document in the training documents buffer 202 as a flag, to indicate that the particular reviewed document is relevant (1) or not relevant (0). In some embodiments, documents that the user considers to be relevant and documents the user considers to be non-relevant are both added to the training buffer 206”). The limitations of claim 5 are rejected in view of the analysis of claim 4 above, and the rationale to combine, as discussed in claim 4, applies here as well.
Claim(s) 10-11 is/are rejected under 35 U.S.C. 103 as being unpatentable over Edwards et al. (Pub. No.: US 20020038430 A1) in view of Martin et al. (Pub. No.: US 20180004942 A1) and further in view of Liao et al. (Patent. No.: US 11444978 B1).
As to claim 10, Edward in view of Martin does not explicitly teach applying score to the documents.
However, in the same field of endeavor (electronic document processing) Liao teaches evaluating documents according to rejection criteria applies a dispensability score to the documents (col. 10, lines 5-16, “…Phishing classifier layers 275 process the URL feature hash, word encoding and image embedding to produce at least one likelihood score that the URL and the content accessed via the URL represents a phishing risk…”).
Based on Edwards in view of Martin and further in view of Liao, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention, to incorporate applying score to the documents (taught by Liao) with detecting pattern in the extracted information (taught by Martin) with document collection and analysis (taught by Edward) in order to accurately detect previously and newly identified security threat in the network as motivated by Martin (paragraph [0017]), and in order to use the score to facilitate the process of filtering of the collected documents.
As to claim 11, Edward in view of Martin does not explicitly teach applying score to the documents.
However, in the same field of endeavor (electronic document processing) Liao teaches evaluating documents according to rejection criteria applies a dispensability score to the documents based on URLs of the documents (col. 10, lines 5-16, “…Phishing classifier layers 275 process the URL feature hash, word encoding and image embedding to produce at least one likelihood score that the URL and the content accessed via the URL represents a phishing risk…”).
Based on Edwards in view of Martin and further in view of Liao, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention, to incorporate applying score to the documents (taught by Liao) with detecting pattern in the extracted information (taught by Martin) with document collection and analysis (taught by Edward) in order to accurately detect previously and newly identified security threat in the network as motivated by Martin (paragraph [0017]), and in order to use the score to facilitate the process of filtering of the collected documents.
Claim(s) 12 is/are rejected under 35 U.S.C. 103 as being unpatentable over Edwards et al. (Pub. No.: US 20020038430 A1) in view of Martin et al. (Pub. No.: US 20180004942 A1) and further in view of Xu et al. (Patent. No.: US 8380693 B1).
As to claim 12, Edward in view of Martin does not explicitly teach applying score to the documents.
However, in the same field of endeavor (electronic document processing) Xu teaches evaluating documents according to rejection criteria applies a dispensability score to the documents based on the presence in the URL of one or more weighted indicator expressions (col. 16, lines 46-67, “…In some embodiments, the details page URL 1102 includes other terms 1110 (or abbreviations) that specifically describe aspects of the detail page posting. These terms or URL tokens are also used in some embodiments in determining a details page score for a details page candidate. For example, in some embodiments, a degree of similarity between URL tokens of a details page candidate and URL tokens of a corpus of known classified website pages is determined, and is then used in determining its details page score”).
Based on Edwards in view of Martin and further in view of Xu, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention, to incorporate applying score to the documents (taught by Xu) with detecting pattern in the extracted information (taught by Martin) with document collection and analysis (taught by Edward) in order to accurately detect previously and newly identified security threat in the network as motivated by Martin (paragraph [0017]), and in order to use the score to facilitate the process of filtering of the collected documents.
Claim(s) 13 is/are rejected under 35 U.S.C. 103 as being unpatentable over Edwards et al. (Pub. No.: US 20020038430 A1) in view of Martin et al. (Pub. No.: US 20180004942 A1) and further in view of Bulusu et al. (Patent. No.: US 10866719 B1).
As to claim 13, Edward in view of Martin does not explicitly teach applying score to the documents.
However, in the same field of endeavor (electronic document processing) Bulusu teaches evaluating documents according to rejection criteria applies a dispensability score to the documents based on a ratio of valuable entities to total token value (col. 10, line 63- col. 11, line 18, “…Information content density may be a ratio of important keywords to total words in a post and may be indicative of a value of the content (e.g., the higher the information content density, the more important the content, etc.)…”).
Based on Edwards in view of Martin and further in view of Bulusu, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention, to incorporate applying score to the documents (taught by Bulusu) with detecting pattern in the extracted information (taught by Martin) with document collection and analysis (taught by Edward) in order to accurately detect previously and newly identified security threat in the network as motivated by Martin (paragraph [0017]), and in order to use the score to facilitate the process of filtering of the collected documents.
Claim(s) 14 is/are rejected under 35 U.S.C. 103 as being unpatentable over Edwards et al. (Pub. No.: US 20020038430 A1) in view of Martin et al. (Pub. No.: US 20180004942 A1) and further in view of Shmueli (Pub. No.: US 20130006948 A1).
As to claim 14, Edward in view of Martin does not explicitly teach applying score to the documents.
However, in the same field of endeavor (electronic document processing) Shmueli teaches evaluating documents according to rejection criteria applies a dispensability score to the documents based on a relationship between true content size and compressed size (paragraph [0006],”…calculating a compression ratio for a file stored on one of the multiple tiers, calculating, using the compression ratio, a priority score for the file…”).
Based on Edwards in view of Martin and further in view of Shmueli, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention, to incorporate applying score to the documents (taught by Shmueli) with detecting pattern in the extracted information (taught by Martin) with document collection and analysis (taught by Edward) in order to accurately detect previously and newly identified security threat in the network as motivated by Martin (paragraph [0017]), and in order to use the score to facilitate the process of filtering of the collected documents.
Claim(s) 15-17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Edwards et al. (Pub. No.: US 20020038430 A1) in view of Martin et al. (Pub. No.: US 20180004942 A1) and further in view of Mahapatra et al. (Pub. No.: US 20230020886 A1).
As to claim 15, Edwards teaches application of heuristics includes utilizing one or more functions to reprocess items in a stream of machine readable documents (paragraph [0014]).
Edward in view of Martin does not explicitly teach utilizing a foundation model.
However, in the same field of endeavor (electronic document processing) Mahapatra teaches application of heuristics includes utilizing one or more foundation models to reprocess items in a stream of machine readable documents (paragraph [0057], “…the text summarization system feeds the input text to the text summarization model that was generated using neural architecture search and knowledge distillation as described hereinabove…”).
Based on Edwards in view of Martin and further in view of Mahapatra, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention, to incorporate utilizing a foundation model (taught by Mahapatra) with detecting pattern in the extracted information (taught by Martin) with document collection and analysis (taught by Edward) in order to accurately detect previously and newly identified security threat in the network as motivated by Martin (paragraph [0017]), and in order to use the foundation model to facilitate the process of filtering of the collected documents.
As to claim 16, Mahapatra further teaches wherein the application of heuristics includes utilizing one or more Large Language Models (LLMs) to reprocess items in a stream of machine readable documents (paragraph [0029], “The knowledge distillation module 112 leverages knowledge from a large language model to inform the search and training of a text summarization model being generated”). The limitations of claim 16 are rejected in view of the analysis of claim 15 above, and the rationale to combine, as discussed in claim 15, applies here as well.
As to claim 17, Mahapatra further teaches wherein the application of heuristics includes utilizing one or more foundation models to gain more information about or summarize items in a stream of machine readable documents (paragraph [0057], “…the text summarization system feeds the input text to the text summarization model that was generated using neural architecture search and knowledge distillation as described hereinabove…”). The limitations of claim 17 are rejected in view of the analysis of claim 15 above, and the rationale to combine, as discussed in claim 15, applies here as well.
Claim(s) 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Edwards et al. (Pub. No.: US 20020038430 A1) in view of Martin et al. (Pub. No.: US 20180004942 A1) and further in view of Weilbacher (Pub. No.: US 20160308890 A1).
As to claim 18, Edwards teaches wherein the continuously gathering and evaluating machine-readable documents operate on a plurality of formats including textual, image, video formatted machine-readable documents (paragraph [0012]).
Edward in view of Martin does not explicitly teach PDF format.
However, in the same field of endeavor (cybersecurity) Weilbacher teaches gathering and evaluating machine-readable documents operate on a plurality of formats including pdf formatted machine-readable documents (paragraph [0056], “ For example, non-limiting example, user interface 340 may display a drop location and the user may drag a PDF of a DHS threat report onto that drop location to manually provide information to cyber-threat device 130”).
Based on Edwards in view of Martin and further in view of Weilbacher, it would have been obvious to a person of ordinary skill in the art, before the effective filing date of the claimed invention, to incorporate evaluating PDF format documents (taught by Weilbacher) with detecting pattern in the extracted information (taught by Martin) with document collection and analysis (taught by Edward) in order to accurately detect previously and newly identified security threat in the network as motivated by Martin (paragraph [0017]), and in order to extend the capability of the collection process which will result in more potential threat discovery.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ABDULKADER M ALRIYASHI whose telephone number is (313)446-6551. The examiner can normally be reached Monday - Friday, 8AM - 5PM Alt, Friday, EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, JOON HWANG can be reached at (571)272-4036. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Abdulkader M Alriyashi/Primary Examiner, Art Unit 2447 5/22/2026