DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 05/13/2026 has been entered. Claims 1-20 have been examined.
Response to Arguments
Applicant’s arguments with respect to claims 1,15 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
With regards to claim objection (Claim 1), Applicant amendment does not overcome the claim objection. – See 112 2nd rejection below.
With regards to claim objection (Claim 13), Applicant amendment overcomes the claim objection. Therefore, the claim objection is withdrawn.
With regards to 112 2nd rejection (Claims 12 &15), Applicant’s amendments overcome the rejection. Therefore, the rejection is withdrawn.
With regards to 112 2nd rejection (Claim 18), Applicant’s amendment does not overcome the rejection. Therefore, the rejection is maintained. See 112 2nd rejection below.
Claim Objections
Claims 1,15 are objected to because of the following informalities:
With regards to claim 1, the claim recites “ an first occurrence” the examiner suggests amending the claim to recite “a first occurrence”.
With regards to claim 15, the claim recites “ a network interface circuit configured to….from a data communication network from a data communication network” The “from a data communication network” is repeated twice. Examiner suggested removing the second “ from a data communication network”.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-14,18 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
With regards claim 1, the claim recites “ the event” it is unclear what the event is referring to because claim 1 recites “network events” . Therefore, the examiner is unable to determine the metes and bounds of the claim language. The examiner suggests amending the claim to recite “an event”
With regards to claim 18, the claim recites “general purpose processor of the network security appliance” It is unclear what the network security appliance is referring to because claim 18 recites “a network security appliance” and claim 15 which claim 18 depends on recites “ a network security appliance”. It is unclear if “the network security appliance” recited in claim 18 refers to “a network security appliance” recited in claim 18 or “ a network security appliance” recited in claim 15. Therefore, the examiner is unable to determine the metes and bounds of the claim language. Examiner suggests amending the claim to recite “ wherein the device is embedded into the network security appliance”.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1,2,5,6,10,11,14,15,20 are rejected under 35 U.S.C. 103 as being unpatentable Guo et al. Patent No. US 11,223,562 (Guo hereinafter ) in view of Li et al. Publication No. US 2016/0149812 (Li hereinafter) further in view of Zhang et al. Publication No.US 2023/0125310 (Zhang hereinafter).
Regarding claim 1,
Guo teaches a method for classifying network events into the first occurrence of the event and the subsequent occurrence of the same event (Fig.2 & Fig.8) the method comprising:
receiving, by a network event classification circuit of a network interface circuit, a network event from a data communication network ( Col.9, lines 1-35 - hardware accelerator 268 may be implemented within NIC 266 to allow the hardware acceleration function to be used by a general-purpose processor 270 as well as other devices that may be co-located in a data center, for example, with the network device 264. Further, NIC 266 may provide traffic classification service and processing services to other host systems or network nodes operatively coupled with the NIC 266 without using the processing of the general-purpose processor 27 - NIC 266 may further include network interface 276 that receives network traffic, and a network processor 274 to process a network flow. In an embodiment, the hardware accelerator 268 can be configured to perform packet classification using a CBF and maintain values of connection rate meters 284. Metering operations can be performed by the hardware accelerator 268 - network processor 216 or hardware accelerator 218 can be configured to receive an incoming packet, extract n-tuple values ( e.g. source IP address, source port, destination IP address, IP address, protocol) of the incoming packet, searches information associated with the n-tuple values using a CBF – Col.6, lines 20-35 - The term "n-tuple" is used herein to describe a set of n elements (e.g., source and/or destination IP address, port, and protocol) present, for example, in the header of a packet that can be used to identify a transport protocol connection
with which the packet is associated.),
[..] extracting, by the network event classification circuit, a transaction identifier identifying the network event; generating, by the network classification circuit, a search command including a subset of the transaction identifier; and executing, by the network classification circuit, the search command, wherein executing the search command includes: hashing the subset of the transaction identifier with a first hash seed to yield a first memory address, and hashing the subset of the transaction identifier with a second hash seed to yield a second memory address (Col.9, lines 60-70 & Col.10, lines 1-10 - The CBF module 306 performs search operations. The n-tuple extracted by the N-tuple header extraction module 304 is fed to CBF module 306. Then-tuple includes a source IP address, destination IP address, layer four protocol, source port, destination port, IP address family and other such information. The CBF module searches the CBF by calculating K hash values by applying K hash functions to the n-tuple values extracted from the packet, reads K memory locations corresponding to the K hash values, wherein each of the K memory locations contains one of the counters, and evaluates whether all K memory locations contain non-zero values. the K hash values point to one of k memory spaces into which the CBF memory has been partitioned. Alternatively, the K hash values may point to the same memory space. Non-limiting examples of hash functions that may be used include Cyclic Redundancy Check (CRC) and exclusive ORs (XORs) with random seeds.Col.12, lines 35-60 - - As shown in FIG. 4, the hash value generated by hash function HO 404, and hash value generated by hash function Hl 406 may act as pointer PTR_0 and PTR_l, to a particular memory space (e.g., Mem O 408 and Mem 1 410). - Then-tuple 402 may include values of one or more of the source IP address, the destination IP address, the layer four protocol, the source port, and the destination port of a packet at issue. All or a portion of then-tuple 402 may be input to multiple hash functions).
generating a classification of the network event based at least in part upon a first value accessed from a memory at the first memory address and a second value accessed from the memory at the second memory address, (Col.12, lines 35-70 - the hash value generated by has function HO 404, and hash value generated by hash function Hl 406 may act as pointer PTR_0 and PTR_l, to a particular memory space (e.g., Mem O 408 and Mem 1 410, respectively) containing one or more counters to be incremented As shown in FIG. the hash function generated pointers may be used to access a memory space associated with the hash function to retrieve an s-bit unsigned integer value representing a counter. Alternatively, the pointers may access a common (non-partitioned) memory space. In one embodiment, when any of the counters are zero, the packet is classified as the first packet of a connection and when all of the counters are non-zero, the packet is classified as a subsequent packet of a previously observed connection).
Guo teaches extracting the transaction identifier and that the classification is transmitted within the network security appliance, wherein the network security appliance performs one or more processes using the classification (Col.9, lines 60-70 ,Col.7, lines 55-60, Col. 8, lines 60-65 – extracting n-tuple values and the network device (e.g. firewall, IDS/IPs) processes the incoming packet based on whether the incoming packet is the first packet or subsequent packet).
However Guo does not explicitly teach generating the transaction Identifier identifying the network event and transmitting the classification to a network security appliance
Li teaches
generating the transaction Identifier identifying the network event (¶0019 - Flow engine 250 receives incoming data packets which can be communication from client devices. Flow engine 250 processes the received data packets to identify the flow associated with the received data packets. ¶ 0025 - the flow engine 250 generates a flow identifier for each received data packet. As described above, the flow identifier uniquely identifies each flow being processed. the flow identifier is therefore referred to as a "flow key." The flow key is generated from the 5-tuple or 6-tuple (or more) information of the received data packets to uniquely associate received data packets belonging to the same flow - See claim 1 - flow engine configured to receive incoming data packets and to generate a flow key identifying a flow to which the received data packet belongs, the flow engine further configured to apply a hash function to the flow key to generate a flow hash value and an entry hash value See also Claim 4).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Li. The motivation for doing so is to allow system to uniquely identify each flow being processed (Li – ¶0025).
Zhang teaches
transmitting the classification to a network security appliance, wherein the network security appliance performs one or more processes using the classification (Abstract - classification of the IoT device is provided to a security appliance configured to apply a policy to the Io T device).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Zhang. The motivation for doing so is to allow system to provide the classification to the security appliance instead of being within the same device in order to provide massive computing power and flexibility that local device cannot match.
Regarding claim 2,
Guo further teaches
performing, by a processing resource, a network process using at least the classification of the network event (Claim 1 - when said determining is affirmative, classifying, by the processing resource, the packet as a subsequent packet of the active transport protocol connection, when said determining is negative: classifying, by the processing resource, the packet as a first packet of a new transport protocol connection - processing, by the processing resource, the packet in accordance with its classification as the first packet or the subsequent packet).
Regarding claim 5,
Guo further teaches
wherein the classification of the network event indicates an initial occurrence, executing, by the network classification circuit, an increment command, wherein executing the increment command includes: incrementing the first value at the first memory address and incrementing the second value at the second memory address (Col. Lines 40-50 - classifies the packet as first packet of a new transport protocol connection when said determination is negative. The incoming packet is classified as the first packet if the value at any of the k memory locations is zero – Claim 1,Fig.10 and Col.2, lines 1-5 -processing resource increments value of those counters of the multiple counters corresponding to the n-tuple values based on said determination. Col.10, lines 1- 30 -reads K memory locations corresponding to the K hash values, wherein each of the K memory locations contains one of the counters ,the value at each of the k memory locations is incremented if the incoming packet is the first packet).
Regarding claim 6,
Guo further teaches
when a search command corresponding to either the first memory address or the second memory address has not been received for a defined period, executing, by the network classification circuit, a decrement command, wherein executing the decrement command includes: decrementing the first value at the first memory address and the second value at the second memory address (Col. 13, lines 15-20 -after a predetermined amount of time or after a predetermined number of packets have been processed, counters that were previously incremented can be decremented. In this manner, when there has been no active CBF search for a particular connection, the counters are gradually cleared – See Claim1, Col.11, lines 20- 30 - The connection rate meter module 312 may increment the values of those counters of the multiple counters corresponding to the n-tuple values associated with a search request and may decrement one or more counters when a decrement event is detected for one or more counters of the multiple counters. In an embodiment, the decrement event includes the retirement queue reaching a predetermined or configurable depth threshold or a timestamp of a top queue entry of the retirement queue meeting a time threshold – See Also claim 10).
Regarding claim 10,
Guo further teaches
wherein generating the classification of the network event based at least in part upon a first value accessed from a memory at the first memory address and a second value accessed from the memory at the second memory address includes: determining that both the first value and the second value are zero; and indicating that the classification of the network event indicates an initial occurrence based at least in part on the determination that both the first value and the second value are zero (Col.3, lines 60-70 & Col.4, lines 1-5 - the CBF receives then-tuple value of the incoming packet, hashes the n-tuple values to calculate k hash values, reads k memory locations corresponding to the k hash values, and determines whether the value at each of the k memory locations is non-zero. The incoming packet is classified as the first packet if the value at any of the k memory locations is zero and the incoming packet is classified as the subsequent packet if the value at each of the k memory locations is non-zero.Col.12, lines 45-60 - each pointer PTR_0 and PTR_l points to a separate memory space, in alternative embodiments, the pointers may be used to access the same memory space. At the time of initialization, the values of all memory locations in Mem O4 08 and Mem 1 410 may be set to zero - when any of the counters are zero, the packet is classified as the first packet of a connection and when all of the counters are non-zero, the packet is classified as a subsequent packet of a previously observed connection).
Regarding claim 11,
Guo further teaches
wherein generating the classification of the network event based at least in part upon a first value accessed from a memory at the first memory address and a second value accessed from the memory at the second memory address includes: determining that at least one of the first value and the second value is greater than zero; and indicating that the classification of the network event indicates a subsequent occurrence based at least in part on the determination that at least one of first value and the second value is greater than zero( Col.12, lines 35-50 - the hash value generated by hash function HO 404, and hash value generated by hash function Hl 406 may act as pointer PTR_0 and PTR_l, to a particular memory space (e.g., Mem O 408 and Mem 1 410, respectively) containing one or more counters to be incremented – Col.3, lines 60-70 & Col.4, lines 1-5 - the CBF receives then-tuple value of the incoming packet, hashes the n-tuple values to calculate k hash values, reads k memory locations corresponding to the k hash values, and determines whether the value at each of the k memory locations is non-zero. The incoming packet is classified as the first packet if the value at any of the k memory locations is zero and the incoming packet is classified as the subsequent packet if the value at each of the k memory locations is non-zero-Col.12, lines 45-60 - each pointer PTR_0 and PTR_l points to a separate memory space, in alternative embodiments, the pointers may be used to access the same memory space. At the time of initialization, the values of all memory locations in Mem O4 08 and Mem 1 410 may be set to zero - when any of the counters are zero, the packet is classified as the first packet of a connection and when all of the counters are non-zero, the packet is classified as a subsequent packet of a previously observed connection).
Regarding claim 14,
Guo further teaches
wherein the network event is a network packet (Col.3, lines 50-55 - a processor on a network device receives an incoming packet ).
Regarding claim 15,
Guo teaches a network event classification device, the device comprising (Fig.2 & Fig.8) the device comprising:
a network interface circuit configured to receive a network event from a data communication network from a data communication network;( Col.9, lines 1-35 - hardware accelerator 268 may be implemented within NIC 266 to allow the hardware acceleration function to be used by a general-purpose processor 270 as well as other devices that may be co-located in a data center, for example, with the network device 264. Further, NIC 266 may provide traffic classification service and processing services to other host systems or network nodes operatively coupled with the NIC 266 without using the processing of the general-purpose processor 27 - NIC 266 may further include network interface 276 that receives network traffic, and a network processor 274 to process a network flow. In an embodiment, the hardware accelerator 268 can be configured to perform packet classification using a CBF and maintain values of connection rate meters 284. Metering operations can be performed by the hardware accelerator 268 - network processor 216 or hardware accelerator 218 can be configured to receive an incoming packet, extract n-tuple values ( e.g. source IP address, source port, destination IP address, IP address, protocol) of the incoming packet, searches information associated with the n-tuple values using a CBF – Col.6, lines 20-35 - The term "n-tuple" is used herein to describe a set of n elements (e.g., source and/or destination IP address, port, and protocol) present, for example, in the header of a packet that can be used to identify a transport protocol connection with which the packet is associated.),
a network processor configured to [..] extracting a transaction identifier identifying the network event; generate a search command including a subset of the transaction identifier; and execute the search command, wherein executing the search command includes: hashing the subset of the transaction identifier with a first hash seed to yield a first memory address, and hashing the subset of the transaction identifier with a second hash seed to yield a second memory address (Col.9, lines 60-70 & Col.10, lines 1-10 - The CBF module 306 performs search operations. The n-tuple extracted by the N-tuple header extraction module 304 is fed to CBF module 306. Then-tuple includes a source IP address, destination IP address, layer four protocol, source port, destination port, IP address family and other such information. The CBF module searches the CBF by calculating K hash values by applying K hash functions to the n-tuple values extracted from the packet, reads K memory locations corresponding to the K hash values, wherein each of the K memory locations contains one of the counters, and evaluates whether all K memory locations contain non-zero values. the K hash values point to one of k memory spaces into which the CBF memory has been partitioned. Alternatively, the K hash values may point to the same memory space. Non-limiting examples of hash functions that may be used include Cyclic Redundancy Check (CRC) and exclusive ORs (XORs) with random seeds.Col.12, lines 35-60 - - As shown in FIG. 4, the hash value generated by hash function HO 404, and hash value generated by hash function Hl 406 may act as pointer PTR_0 and PTR_l, to a particular memory space (e.g., Mem O 408 and Mem 1 410). - Then-tuple 402 may include values of one or more of the source IP address, the destination IP address, the layer four protocol, the source port, and the destination port of a packet at issue. All or a portion of then-tuple 402 may be input to multiple hash functions).
generating a classification of the network event based at least in part upon a first value accessed from a memory at the first memory address and a second value accessed from the memory at the second memory address, wherein the classification indicates whether the network event is an initial occurrence or a subsequent occurrence of a same event;, (Col.12, lines 35-70 - the hash value generated by has function HO 404, and hash value generated by hash function Hl 406 may act as pointer PTR_0 and PTR_l, to a particular memory space (e.g., Mem O 408 and Mem 1 410, respectively) containing one or more counters to be incremented As shown in FIG. the hash function generated pointers may be used to access a memory space associated with the hash function to retrieve an s-bit unsigned integer value representing a counter. Alternatively, the pointers may access a common (non-partitioned) memory space. In one embodiment, when any of the counters are zero, the packet is classified as the first packet of a connection and when all of the counters are non-zero, the packet is classified as a subsequent packet of a previously observed connection).
Guo teaches extracting the transaction identifier and that the classification is transmitted within the network security appliance and wherein the network security appliance performs one or more processes using the classification (Col.9, lines 60-70 ,Col.7, lines 55-60, Col. 8, lines 60-65 – extracting n-tuple values and the network device (e.g. firewall, IDS/IPs) processes the incoming packet based on whether the incoming packet is the first packet or subsequent packet).
However Guo does not explicitly teach generating the transaction Identifier identifying the network event and transmitting the classification to a network security appliance
Li teaches
generating the transaction Identifier (¶ 0019 - Flow engine 250 receives incoming data packets which can be communication from client devices. Flow engine processes the received data packets to identify the flow associated with the received data packets. ¶ 0025 - the flow engine generates a flow identifier for each received data packet. As described above, the flow identifier uniquely identifies each flow being processed. the flow identifier is therefore referred to as a "flow key." The flow key is generated from the 5-tuple or 6-tuple (or more) information of the received data packets to uniquely associate received data packets belonging to the same flow - See claim 1 - flow engine configured to receive incoming data packets and to generate a flow key identifying a flow to which the received data packet belongs, the flow engine further configured to apply a hash function to the flow key to generate a flow hash value and an entry hash value See Claim 4).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Li. The motivation for doing so is to allow system to uniquely identify each flow being processed (Li – ¶0025).
Zhang teaches
transmitting the classification to a network security appliance, wherein the network security appliance performs one or more processes using the classification (Abstract - classification of the IoT device is provided to a security appliance configured to apply a policy to the Io T device).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Zhang. The motivation for doing so is to allow system to provide the classification to the security appliance instead of being within the same device in order to provide massive computing power and flexibility that local device cannot match.
Regarding claim 20,
Guo further teaches
wherein the classification of the network event indicates an initial occurrence, and wherein the network processor is further configured to: execute an increment command, wherein executing the increment command includes: incrementing the first value at the first memory address and incrementing the second value at the second memory address(Col. 10, Lines 40-50 - classifies the packet as first packet of a new transport protocol connection when said determination is negative. The incoming packet is classified as the first packet if the value at any of the k memory locations is zero – Claim 1,Fig.10 and Col.2, lines 1-5 -processing resource increments value of those counters of the multiple counters corresponding to the n-tuple values based on said determination. Col.10, lines 1- 30 -reads K memory locations corresponding to the K hash values, wherein each of the K memory locations contains one of the counters ,the value at each of the k memory locations is incremented if the incoming packet is the first packet
Claims 3,16-19 are rejected under 35 U.S.C. 103 as being unpatentable over Guo in view of Li further in view of Zhang further in view of Lan et al. Publication No. US 2021/0303984 A1 ( Lan hereinafter)
Regarding claim 3,
Guo further teaches wherein the network process is selected from a group consisting of: a denial of service attack detection process (Col.5, lines 30-35 & lines 60-65). However, Guo does not explicitly teach
wherein the network process is selected from a group consisting of: a denial of service attack detection process, and a network transaction logging process
However, Lan teaches
wherein the network process is selected from a group consisting of: a denial of service attack detection process, and a network transaction logging process (¶0044 - The network security device may reside within the particular network that it is protecting, or network security may be provided as a service with the network security device residing in the cloud. Non-limiting examples of security functions include. intrusion detection, denial of service attack (DoS) detection, logging).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Lan. The motivation for doing so is to allow system to classify encrypted network traffic data ( ¶ 0002 – Lan).
Regarding claim 16,
Guo further teaches wherein the device is implemented as a network interface card, and wherein the network interface card (Fig.2C).
However, Guo does not explicitly teach
wherein the network interface card includes a first general purpose processor configured to interface with a second general purpose processor of a network security appliance.
However, Lan teaches
device is implemented as a network interface card, and wherein the network interface card includes a first general purpose processor configured to interface with a second general purpose processor of a network security appliance (¶ 0037 - Fig.1B – device is implemented as NIC and NIC includes processor configured to interface with second processor of network security device 102).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Lan. The motivation for doing so is to allow system to classify encrypted network traffic data ( ¶ 0002 – Lan).
Regarding claim 17,
Guo further teaches
wherein the second general purpose processor is communicably coupled to a non-transitory computer readable medium having stored therein instructions which when executed by the second general purpose processor causes the second general purpose processor to: perform a network process using at least the classification of the network event, and wherein the network process is selected from a denial of service attack detection process (Claim 12 - non-transitory computer-readable medium, coupled to the processing resource, having stored therein instructions that when executed by the processing resource cause the processing resource to: process the packet in accordance with its classification as the first packet or the subsequent packet.Col.2, lines 20-30 - For processing the packet further, the network device makes a determination regarding whether the subsequent packet is part of a denial of service (DoS) attack, and drops the subsequent packet if its determined to be part of the denial of server attack. The denial of service attack may include a Transmission Control Protocol (TCP) SYN flood or a port scan attack).
However, Guo does not explicitly teach
wherein the second general purpose processor is communicably coupled to a non-transitory computer readable medium having stored therein instructions which when executed by the second general purpose processor causes the second general purpose processor to perform a network process using at least the classification of the network event, and wherein the network process is selected from a group consisting of: a denial of service attack detection process, and a network transaction logging process
Lan teaches
wherein the second general purpose processor is communicably coupled to a non-transitory computer readable medium having stored therein instructions which when executed by the second general purpose processor causes the second general purpose processor to perform a network process using at least the classification of the network event, and wherein the network process is selected from a group consisting of: a denial of service attack detection process, and a network transaction logging process (Fig.1B, ¶ 0037, ¶ 0027 - The network security device may reside within the particular network that it is protecting, or network security may be provided as a service with the network security device residing in the cloud. Non-limiting examples of security functions include. intrusion detection, denial of service attack (DoS) detection, logging
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Lan. The motivation for doing so is to allow system to classify encrypted network traffic data ( ¶ 0002 – Lan).
Regarding claim 18,
Guo further teaches
device is embedded into a network security appliance (Col. 7, lines 40-45 - The network device 104 may include a hardware accelerator module 206. In one embodiment the CBF may be implemented by the hardware accelerator module 206 to facilitate efficient packet classification and/or further processing relating to the packet based on defined policies. The network device 104 may have other processing resources, including one or more of a network processor, an embedded processor and/or a general-purpose processor to perform different functions. In the text of the present example, the network device 204 may represent a network security device (e.g., a firewall appliance, a UTM appliance, an IDS/IPS, or the like) and includes a network interface 206 that can act as a point of interconnection between network device 204 and a network 202)
However, Guo does not explicitly teach where the network processor is coupled to a general purpose processor of the network security appliance
However, Lan teaches
wherein the device is imbedded into a network security appliance, and where the network processor is coupled to a general purpose processor of the network security appliance(¶ 0031 - Fig.1A – device is embedded in to network security device 102 , and the network processor 112 is coupled to general purpose processor 104).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Lan. The motivation for doing so is to allow system to classify encrypted network traffic data ( ¶ 0002 – Lan).
Regarding claim 19,
Guo further teaches
wherein the general purpose processor is communicably coupled to a non-transitory computer readable medium having stored therein instructions which when executed by the general purpose processor causes the general purpose processor to: perform a network process using at least the classification of the network event. wherein the network process is selected from: a denial of service attack detection process (Claim 12 - non-transitory computer-readable medium, coupled to the processing resource, having stored therein instructions that when executed by the processing resource cause the processing resource to: process the packet in accordance with its classification as the first packet or the subsequent packet.Col.2, lines 20-30 - For processing the packet further, the network device makes a determination regarding whether the subsequent packet is part of a denial of service (DoS) attack, and drops the subsequent packet if its determined to be part of the denial of server attack. The denial of service attack may include a Transmission Control Protocol (TCP) SYN flood or a port scan attack).
However, Guo does not explicitly teach
wherein the network process is selected from a group consisting of: a denial of service attack detection process, and a network transaction logging process
Lan teaches
wherein the general purpose processor is communicably coupled to a non-transitory computer readable medium having stored therein instructions which when executed by the general purpose processor causes the general purpose processor to: perform a network process using at least the classification of the network event, and wherein the network process is selected from a group consisting of: a denial of service attack detection process, and a network transaction logging process (Fig.1B, ¶ 0037, ¶ 0027 - The network security device may reside within the particular network that it is protecting, or network security may be provided as a service with the network security device residing in the cloud. Non-limiting examples of security functions include. intrusion detection, denial of service attack (DoS) detection, logging
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Lan. The motivation for doing so is to allow system to classify encrypted network traffic data ( ¶ 0002 – Lan).
Claim 4 is rejected under 35 U.S.C. 103 as being unpatentable Guo in view of Li further in view of Zhang further in view of Guleria et al. Publication No. US 2016/0285753 A2 ( Guleria hereinafter)
Regarding claim 4,
Guo does not explicitly teach
wherein the memory is organized into a plurality of tables, wherein the subset of the transaction identifier is a first subset of the transaction identifier, and wherein the method further comprises: enabling, by the network classification circuit, a memory table of the plurality of tables, wherein the memory table is selected based at least in part on a second subset of the transaction identifier.
However, Guleria teaches
a memory is organized into a plurality of tables, wherein the subset of the transaction identifier is a first subset of the transaction identifier, and wherein the method further comprises: enabling, by the network classification circuit, a memory table of the plurality of tables, wherein the memory table is selected based at least in part on a second subset of the transaction identifier (¶ 0030 - Packet classification involves executing a lookup in memory to classify the packet by determining which flow entry in the forwarding tables best matches the packet based upon the match structure, or key, of the flow entries – ¶ 0039 - Upon receipt of a packet of a flow of packets at the network device, it is determined, based on an identification of the flow, whether the packet has a corresponding forwarding table entry within a set of one or more forwarding tables of the network device. If the packet is determined not to have any corresponding forwarding table entry (i.e., the packet belongs to an unknown flow, which is to be inserted in a forwarding table), a flow learning element is retrieved from a flow learning table using a first portion of the flow identification. A second portion of the flow identification for the received packet is used to determine whether the flow of the packet is currently being learnt. In response to determining that the second portion matches a sub-element of the retrieved flow learning element - ¶ 0049 – 0052 Alternatively if the second portion of the flow identification does not match any sub-element of the flow learning element 520 which has a "used" bit set, this means that the flow is not being learnt by the forwarding device and an entry needs to be inserted in the flow learning table 500 See Also – ¶ 0069).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Guleria. The motivation for doing so is to allow system to provide techniques which avoid sending multiple requests to the control plane in order to learn the same flow and to avoid delays in the processing of new flow entries ( ¶ 0004 – Guleria).
Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over Guo in view of Li further in view of Zhang further in view of Panwar et al. Patent No. US 7,966,442 B1 ( Panwar hereinafter)
Regarding claim 7,
Guo does not explicitly teach
wherein the defined period is user programmable
However, Panwar teaches
defined period is user programmable ( Col.10, lines 1-10 an administrator may set the update period to one day or one hour).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Panwar. The motivation for doing so is to allow user to set the period for tracking purposes.
Claims 8,9 are rejected under 35 U.S.C. 103 as being unpatentable over Guo in view of Li further in view of Zhang further in view of Verplanken et al. Publication No. US 2021/0124694 A1 ( Verplanken hereinafter)
Regarding claim 8,
Guo does not explicitly teach
as part of the executing the increment command, queuing, by the network classification circuit, a decrement command
However, Verplanken teaches
as part of the executing the increment command, queuing, by the network classification circuit, a decrement command (¶ 0009 - in which when an increment request to increment the at least one counter is pending, the cache control circuitry is configured to prioritize the pending increment request in preference over a decrement request to decrement the at least one counter- ¶ 0015 - when an increment request to increment the at least one counter is pending, prioritizing the pending increment request in preference over a decrement request to decrement the at least one counter – ¶ 0031 - FIG. 9 is a flow diagram illustrating a method for allocating decrement requests to a decrement request buffer – ¶ 0043 - if two decrement/increment requests can be carried out per processing cycle, the cache control circuitry may delay the decrement request until a cycle in which either no increment requests are being processed, or only one increment request is being processed).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Verplanken. The motivation for doing so is to allow system to prioritize the pending increment request in preference over a decrement request to decrement the at least one counter (¶ 0015 - Verplanken)
Regarding claim 9,
Guo further teaches
determining, by the network classification circuit, a time expiration of the decrement command; and based at least in part on the time expiration, executing, by the network classification circuit, the decrement command, wherein executing the decrement command includes: decrementing the first value at the first memory address and the second value at the second memory address (Col 16, lines 50-60 - those counters of the multiple counters
corresponding to the n-tuple values are incremented. For example, the various n-tuple values may be fed into k separate hash functions to produce k hash value pointers that identify the respective counters in a partitioned or nonpartitioned
memory of the CBF. At block 1016, responsive to a decrement event for one or more counters in the CBF memory, the counters are decremented. As noted above, the decrement event may represent the retirement queue (e.g., FIFO 412) reaching a depth threshold or a timestamp of a tape queue entry of the retirement queue meeting a time threshold).
Claims 12,13 are rejected under 35 U.S.C. 103 as being unpatentable over Guo in view of Li further in view of Zhang further in view of Verplanken further in view of Heo et al. Publication No. US 2021/0374131 A1 ( Heo hereinafter)
Regarding claim 12,
Guo does not explicitly teach
wherein the search command is stored in a search command queue, the increment command is stored in an increment command queue, and the decrement command is stored to a decrement command queue.
However, Verplanken teaches
the increment command is stored in an increment command queue, and the decrement command is stored to a decrement command queue ( ¶ 0098- The cache control circuitry 102 prioritizes pending increment requests to any of the counters stored in the SRAM over the decrement requests stored in the decrement request buffer 110, for example by waiting until a processing cycle in which no increment requests are executed ( e.g. a cycle in which no allocations to the cache are made) to process the next decrement request in the decrement request buffer 110. It should be noted that increment requests to any of the stored counters are prioritized over decrement requests to any of the stored counters, even if the decrement request is to another one of the stored counters, rather than merely prioritizing increment requests to a given counter over decrement requests to that same counter).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Verplanken. The motivation for doing so is to allow system to prioritize the pending increment request in preference over a decrement request to decrement the at least one counter (¶ 0015 - Verplanken)
However, Guo in view of Verplanken does not explicitly teach wherein the search command is stored in a search command queue
Heo teaches
search command is stored in a search command queue (¶ 0065 - The command queue 110 sequentially stores search commands)
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo in view of Verplanken to include the teachings of Heo. The motivation for doing so is to allow the system to store search commands in command queue for processing ( Heo – ¶ 0065).
Regarding claim 13,
Guo does not explicitly teach
wherein accessing a command by the network classification circuit from one of the search command queue, the increment command queue, or the decrement command queue is based upon a priority algorithm, and wherein the priority algorithm causes all commands in the increment command queue to be executed before any command in either the search command queue or the decrement command queue.
However, Verplanken teaches
wherein accessing a command by the network classification circuit from one of the search command queue, the increment command queue, or the decrement command queue is based upon a priority algorithm, and wherein the priority algorithm causes all commands in the increment command queue to be executed before any command in either the search command queue or the decrement command queue (¶ 0009 - in which when an increment request to increment the at least one counter is pending, the cache control circuitry is configured to prioritize the pending increment request in preference over a decrement request to decrement the at least one counter – ¶ 0037 -Prioritizing requests to increment the counters over requests to decrement the counters allows the performance of the system to be further improved - ¶ 0098- The cache control circuitry 102 prioritizes pending increment requests to any of the counters stored in the SRAM over the decrement requests stored in the decrement request buffer 110, for example by waiting until a processing cycle in which no increment requests are executed ( e.g. a cycle in which no allocations to the cache are made) to process the next decrement request in the decrement request buffer 110. It should be noted that increment requests to any of the stored counters are prioritized over decrement requests to any of the stored counters, even if the decrement request is to another one of the stored counters, rather than merely prioritizing increment requests to a given counter over decrement requests to that same counter).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Guo to include the teachings of Verplanken. The motivation for doing so is to allow system to prioritize the pending increment request in preference over a decrement request to decrement the at least one counter (¶ 0015 - Verplanken).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to YOUNES NAJI whose telephone number is (571)272-2659. The examiner can normally be reached Monday - Friday 8:30 AM -5:30 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Oscar A Louie can be reached on (571) 270-1684. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/YOUNES NAJI/Primary Examiner, Art Unit 2445