DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statement filed 30 August 2023 fails to comply with 37 CFR 1.98(a)(2), which requires a legible copy of each cited foreign patent document; each non-patent literature publication or that portion which caused it to be listed; and all other information or that portion which caused it to be listed. In particular, foreign patent citation number 5, EP3841712, has only been submitted with an abstract; however, no copy of the patent document itself has been submitted. The IDS has been placed in the application file, and the information referred to therein has been considered, with the exception of the document noted above.
Drawings
The drawings are objected to as failing to comply with 37 CFR 1.84(p)(5) because they do not include the following reference sign(s) mentioned in the description: 115 (see paragraph 0044). Corrected drawing sheets in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance.
The drawings are objected to because they include informalities. For example, in Figures 1 and 2, element 104, “Maliciouis” should read “Malicious”. In Figures 1 and 2, element 130, “Acces” should read “Access”. In Figures 4 and 5, the text is too small to be clearly legible. In Figure 4, element 400, and Figure 5, element 500, these do not appear to clearly be steps in the flowchart; rather, it appears that these reference numerals may be intended to refer to the flowcharts as a whole. In Figure 4, step 428, and Figure 5, step 534, it is not clear why these steps are indicated using ovals in contrast with the rectangles used for the remaining steps. Corrected drawing sheets in compliance with 37 CFR 1.121(d) are required in reply to the Office action to avoid abandonment of the application. Any amended replacement drawing sheet should include all of the figures appearing on the immediate prior version of the sheet, even if only one figure is being amended. The figure or figure number of an amended drawing should not be labeled as “amended.” If a drawing figure is to be canceled, the appropriate figure must be removed from the replacement sheet, and where necessary, the remaining figures must be renumbered and appropriate changes made to the brief description of the several views of the drawings for consistency. Additional replacement sheets may be necessary to show the renumbering of the remaining figures. Each drawing sheet submitted after the filing date of an application must be labeled in the top margin as either “Replacement Sheet” or “New Sheet” pursuant to 37 CFR 1.121(d). If the changes are not accepted by the examiner, the applicant will be notified and informed of any required corrective action in the next Office action. The objection to the drawings will not be held in abeyance.
Specification
The disclosure is objected to because of the following informalities:
The specification includes minor grammatical and other errors. For example, several acronyms or abbreviations are used without being defined/written out in full the first time they are used. See at least paragraph 0003, ATM; paragraph 0004, PPPoA and PPPoE; and paragraph 0035, CRON. In paragraph 0047, line 1, it appears that “in bound” may be intended to read “inbound”.
Appropriate correction is required. The above is not intended as an exhaustive list of errors in the specification. Applicant’s cooperation is requested in correcting any errors of which applicant may become aware in the specification.
The use of the term Java, which is a trade name or a mark used in commerce, has been noted in this application. The term should be accompanied by the generic terminology; furthermore the term should be capitalized wherever it appears or, where appropriate, include a proper symbol indicating use in commerce such as ™, SM , or ® following the term.
Although the use of trade names and marks used in commerce (i.e., trademarks, service marks, certification marks, and collective marks) is permissible in patent applications, the proprietary nature of the marks should be respected and every effort made to prevent their use in any manner which might adversely affect their validity as commercial marks.
Claim Objections
Claims 1, 16, and 20 are objected to because of the following informalities:
In Claim 1, lines 11, 12, 14, 17, 19, and 22, the commas at the end of each list item should be replaced by semicolons, because some items in the list include internal commas.
In Claim 1, line 23, one of the repeated words “the the” should be deleted.
In Claim 16, lines 11, 12, 13, 16, 18, and 21, the commas at the end of each list item should be replaced by semicolons, because some items in the list include internal commas.
In Claim 16, line 22, one of the repeated words “the the” should be deleted.
In Claim 20, lines 11, 12, 13, 16, 18, and 21, the commas at the end of each list item should be replaced by semicolons, because some items in the list include internal commas.
In Claim 20, line 22, one of the repeated words “the the” should be deleted.
In Claim 20, line 36, “Deploying” should be replaced with “deploying”.
Appropriate correction is required.
Applicant is advised that should Claim 16 be found allowable, Claim 20 will be objected to under 37 CFR 1.75 as being a substantial duplicate thereof. When two claims in an application are duplicates or else are so close in content that they both cover the same thing, despite a slight difference in wording, it is proper after allowing one claim to object to the other as being a substantial duplicate of the allowed claim. See MPEP § 608.01(m). Although Claim 20 recites the term “real-time” in line 1, there is nothing in the body of the claim that provides any structure or functionality for implementing the process in real time. Claim 20 is otherwise identical to Claim 16.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1-20 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
Claim 1 recites “An information-security, border-endpoint process to block a zero-day threat comprising the steps of” in lines 1-2. The subject of the verb “comprising” is not grammatically clear. The claim further recites that traffic “appears unsolicited” in line 19 or that traffic “appears anomalous” in lines 21-22. The term “appears” is subjective and is not clearly defined in the specification. No standard of comparison is provided to be able to determine whether traffic may “appear” to be unsolicited or anomalous or what this may entail. See MPEP § 2173.05(b). The claim further recites “unauthorized data” in line 25. It is not clear by who or by what the data would need to be authorized, and the specification does not provide any definition or standard for this. The claim further recites “the suspect traffic” in lines 28, 29, and elsewhere. However, if suspect traffic was not detected, then it is not clear to what this phrase is intended to refer or if the various steps acting on the suspect traffic could be performed. The claim additionally recites determining “whether the suspect traffic is an advanced persistent threat (APT)” in lines 29-30. However, it is not clear how traffic itself would be an APT since it appears that an APT could at most be the source of suspect traffic based on the specification. The claim also recites “said APT” in lines 32 and 34, and “the APT” in lines 36, 38, and elsewhere. However, the claim only recited determining whether suspect traffic is an APT, which does not appear to refer to a specific threat, and therefore, the recitations of “said APT” and “the APT” are not clear as to what particular threat they are intended to refer. The claim further recites “disabling, by the endpoint supervisory server based the suspect traffic, any said network border control device that was compromised by the APT” in lines 39-40. First, the phrase “based the suspect traffic” is grammatically unclear, although it appears that this may be intended to read “based on the suspect traffic”. Further, the reference to “any said network border control device” is unclear because there were not clearly plural devices recited previously. Additionally, it is not clear when a compromise of a device is required to have occurred; the relative timing of the compromise is not clear. The claim further recites “said network border control device” in lines 42, 44, and elsewhere. Because it appears that there are plural such devices recited in lines 39-40, the subsequent references are unclear to which of the plural devices these phrases are intended to refer. The claim additionally recites “the source information for the APT” in lines 42-43. There is not clear antecedent basis for this limitation in the claim, although it appears that this may be intended to refer to the source information regarding the APT. The claim also recites “searching, said network border control device” in line 44. First, the comma after “searching” is grammatically unclear. Further, it is not clear what the device is searched for. The claim further recites “the endpoint supervisor server in said network border control device” in line 46. There is not clear antecedent basis for this limitation in the claim. Although the claim previously recited an endpoint supervisory server, this was not clearly in a network border control device. The claim additionally recites “so that the captured data cannot be removed from the APT from the network border control device” in lines 47-48. It is not grammatically clear what the phrase “from the network border control device” is intended to modify. The claim also recites “updating, by the endpoint supervisory server, the AI analyzer” in line 49. It is not clear how this updating is distinct from the updating in line 37 and whether this is a separate step of updating. Further, it is not clear whether the two steps of updating both operate on the same version of AI analyzer or if they are sequential. The claim further recites “when the zero-day threat becomes known” in line 50. The timing of this is not clear. The claim additionally recites “generating, by the endpoint supervisory server to a developer of the software, a notification regarding the vulnerabilities in order resolve said zero-day threat” in lines 51-52. First, it is not grammatically clear what the phrase “to a developer” is intended to modify. Further, it appears that the phrase “in order resolve” should read “in order to resolve”. Additionally, it is not clear how a notification would resolve the threat. The above ambiguities render the claim indefinite.
Claim 2 recites “the network border control device of Claim 1” in line 1. First, Claim 1 is directed to a process, not a border control device. Further, Claim 1 appears to recite plural border control devices, and it is not clear to which of the plural devices this limitation is intended to refer.
Claim 3 recites “the network border control device of Claim 1” in line 1. First, Claim 1 is directed to a process, not a border control device. Further, Claim 1 appears to recite plural border control devices, and it is not clear to which of the plural devices this limitation is intended to refer.
Claim 4 recites “the network border control device of Claim 1” in line 1. First, Claim 1 is directed to a process, not a border control device. Further, Claim 1 appears to recite plural border control devices, and it is not clear to which of the plural devices this limitation is intended to refer.
Claim 10 recites “the tracing of the source information” in line 1. However, although Claim 1 recited tracing suspect traffic, there is not clear antecedent basis in the claims for tracing source information. Claim 10 further recites “the APT” in line 2. It is not clear that the APT in Claim 1 referred to a specific threat.
Claim 11 recites a step of “learning, by the AI analyzer, based on the source information for the APT and the suspect traffic confirmed to present said APT” in lines 1-3, but it is not clear what is learned. Further, it is not grammatically clear how the phrase “confirmed to present said APT” is related to the remainder of the claim or what the phrase is intended to modify.
Claim 16 recites “An information-security border-endpoint process to block a zero-day threat comprising the steps of” in lines 1-2. The subject of the verb “comprising” is not grammatically clear. The claim further recites that traffic “appears unsolicited” in line 18 or that traffic “appears anomalous” in lines 20-21. The term “appears” is subjective and is not clearly defined in the specification. No standard of comparison is provided to be able to determine whether traffic may “appear” to be unsolicited or anomalous or what this may entail. See MPEP § 2173.05(b). The claim further recites “unauthorized data” in line 24. It is not clear by who or by what the data would need to be authorized, and the specification does not provide any definition or standard for this. The claim further recites “the suspect traffic” in lines 27, 28, and elsewhere. However, if suspect traffic was not detected, then it is not clear to what this phrase is intended to refer or if the various steps acting on the suspect traffic could be performed. The claim additionally recites determining “whether the suspect traffic is an advanced persistent threat (APT)” in lines 28-29. However, it is not clear how traffic itself would be an APT since it appears that an APT could at most be the source of suspect traffic based on the specification. The claim also recites “said APT” in lines 31 and 33, and “the APT” in lines 35, 37, and elsewhere. However, the claim only recited determining whether suspect traffic is an APT, which does not appear to refer to a specific threat, and therefore, the recitations of “said APT” and “the APT” are not clear as to what particular threat they are intended to refer. The claim further recites “disabling, by the endpoint supervisory server based the suspect traffic, any said firewall that was compromised by the APT” in lines 40-41. First, the phrase “based the suspect traffic” is grammatically unclear, although it appears that this may be intended to read “based on the suspect traffic”. Further, the reference to “any said firewall” is unclear because there were not clearly plural firewalls recited previously. Additionally, it is not clear when a compromise of a firewall is required to have occurred; the relative timing of the compromise is not clear. The claim further recites “said firewall” in lines 43, 44, and elsewhere. Because it appears that there are plural firewalls recited in lines 40-41, the subsequent references are unclear to which of the plural devices these phrases are intended to refer. The claim additionally recites “the source information for the APT” in line 43. There is not clear antecedent basis for this limitation in the claim, although it appears that this may be intended to refer to the source information regarding the APT. The claim also recites “searching, said firewall” in line 44. First, the comma after “searching” is grammatically unclear. Further, it is not clear what the firewall is searched for. The claim further recites “the endpoint supervisor server in said firewall” in line 46. There is not clear antecedent basis for this limitation in the claim. Although the claim previously recited an endpoint supervisory server, this was not clearly in a firewall. The claim additionally recites “so that the captured data cannot be removed from the APT from the firewall” in lines 47-48. It is not grammatically clear what the phrase “from the firewall” is intended to modify. The claim also recites “updating, by the endpoint supervisory server, the AI analyzer” in line 49. It is not clear how this updating is distinct from the updating in line 38 and whether this is a separate step of updating. Further, it is not clear whether the two steps of updating both operate on the same version of AI analyzer or if they are sequential. The claim further recites “when the zero-day threat becomes known” in line 50. The timing of this is not clear. The claim additionally recites “generating, by the endpoint supervisory server to a developer of the software, a notification regarding the vulnerabilities in order resolve said zero-day threat” in lines 51-52. First, it is not grammatically clear what the phrase “to a developer” is intended to modify. Further, it appears that the phrase “in order resolve” should read “in order to resolve”. Additionally, it is not clear how a notification would resolve the threat. The above ambiguities render the claim indefinite.
Claim 20 recites “A real-time, information-security, border-endpoint process to block a zero-day threat comprising the steps of” in lines 1-2. The subject of the verb “comprising” is not grammatically clear. The claim further recites that traffic “appears unsolicited” in line 18 or that traffic “appears anomalous” in lines 20-21. The term “appears” is subjective and is not clearly defined in the specification. No standard of comparison is provided to be able to determine whether traffic may “appear” to be unsolicited or anomalous or what this may entail. See MPEP § 2173.05(b). The claim further recites “unauthorized data” in line 24. It is not clear by who or by what the data would need to be authorized, and the specification does not provide any definition or standard for this. The claim further recites “the suspect traffic” in lines 27, 28, and elsewhere. However, if suspect traffic was not detected, then it is not clear to what this phrase is intended to refer or if the various steps acting on the suspect traffic could be performed. The claim additionally recites determining “whether the suspect traffic is an advanced persistent threat (APT)” in lines 28-29. However, it is not clear how traffic itself would be an APT since it appears that an APT could at most be the source of suspect traffic based on the specification. The claim also recites “said APT” in lines 31 and 33, and “the APT” in lines 35, 37, and elsewhere. However, the claim only recited determining whether suspect traffic is an APT, which does not appear to refer to a specific threat, and therefore, the recitations of “said APT” and “the APT” are not clear as to what particular threat they are intended to refer. The claim further recites “disabling, by the endpoint supervisory server based the suspect traffic, any said firewall that was compromised by the APT” in lines 40-41. First, the phrase “based the suspect traffic” is grammatically unclear, although it appears that this may be intended to read “based on the suspect traffic”. Further, the reference to “any said firewall” is unclear because there were not clearly plural firewalls recited previously. Additionally, it is not clear when a compromise of a firewall is required to have occurred; the relative timing of the compromise is not clear. The claim further recites “said firewall” in lines 43, 44, and elsewhere. Because it appears that there are plural firewalls recited in lines 40-41, the subsequent references are unclear to which of the plural devices these phrases are intended to refer. The claim additionally recites “the source information for the APT” in line 43. There is not clear antecedent basis for this limitation in the claim, although it appears that this may be intended to refer to the source information regarding the APT. The claim also recites “searching, said firewall” in line 44. First, the comma after “searching” is grammatically unclear. Further, it is not clear what the firewall is searched for. The claim further recites “the endpoint supervisor server in said firewall” in line 46. There is not clear antecedent basis for this limitation in the claim. Although the claim previously recited an endpoint supervisory server, this was not clearly in a firewall. The claim additionally recites “so that the captured data cannot be removed from the APT from the firewall” in lines 47-48. It is not grammatically clear what the phrase “from the firewall” is intended to modify. The claim also recites “updating, by the endpoint supervisory server, the AI analyzer” in line 49. It is not clear how this updating is distinct from the updating in line 38 and whether this is a separate step of updating. Further, it is not clear whether the two steps of updating both operate on the same version of AI analyzer or if they are sequential. The claim further recites “when the zero-day threat becomes known” in line 50. The timing of this is not clear. The claim additionally recites “generating, by the endpoint supervisory server to a developer of the software, a notification regarding the vulnerabilities in order resolve said zero-day threat” in lines 51-52. First, it is not grammatically clear what the phrase “to a developer” is intended to modify. Further, it appears that the phrase “in order resolve” should read “in order to resolve”. Additionally, it is not clear how a notification would resolve the threat. The above ambiguities render the claim indefinite.
Claims not explicitly referred to above are rejected due to their dependence on a rejected base claim.
Allowable Subject Matter
Claims 1-20 would be allowable if rewritten or amended to overcome the rejections under 35 U.S.C. 112(b) set forth in this Office action.
The following is a statement of reasons for the indication of allowable subject matter:
Each of independent Claims 1, 16, and 20 recites a step of detecting suspect traffic by an AI analyzer if the external-outbound traffic does not correlate to the internal-outbound traffic; the external-inbound traffic does not correlate to the internal-inbound traffic; the external-inbound traffic does not have a destination beyond the network border control device; the external-outbound traffic, the external-inbound traffic, the internal-outbound traffic, or the internal-inbound traffic match a historical suspect traffic pattern; the external-outbound traffic, the external-inbound traffic, the internal- outbound traffic, or the internal-inbound traffic appears unsolicited; a pattern of traffic for the external-outbound traffic, the external-inbound traffic, the internal-outbound traffic, or the internal-inbound traffic appears anomalous; and any payload in the external-outbound traffic, the external-inbound traffic, the internal-outbound traffic, or the internal-inbound traffic contains malware or unauthorized data (emphasis added). The use of the conjunction “and” indicates that all of the conditions are required to detect suspect traffic. None of the cited art (see below), alone or in combination, clearly teaches or suggests detecting suspect traffic only when all of the recited conditions occur. Therefore, the claims would be allowable over the cited prior art if the rejections under 35 U.S.C. 112(b) were overcome.
It is noted that amendments that substantially change the scope of the claims may require reconsideration of the above indication of allowable subject matter.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Culbert, US Patent 7512781, discloses a device having a firewall that inspects incoming and outgoing internal and external packets.
Stolfo et al, US Patent 7639714, discloses a method that includes inspecting and comparing inbound and outbound packets.
Feghali et al, US Patent 9407602, discloses a system using an inspector to compare incoming and outgoing packets.
Heilig, US Patent 10313372, discloses a technique for comparing inbound and outbound network traffic to discover packets violating rules.
George et al, US Patent 10374913, discloses a method that includes comparing flows of packets seen on each side of a gateway.
Chernick et al, US Patent 11848953, discloses a system monitoring for network compromise using firewall traffic.
Trcka et al, US Patent Application Publication 2001/0039579, discloses a system that compares external and internal traffic of a firewall.
Bu et al, US Patent Application Publication 2014/0380473, discloses a system for determining a zero-day attack.
Suzuki, US Patent Application Publication 2015/0256455, discloses a system that collates packets using external and internal border gateway protocols.
Chesla, US Patent Application Publication 2016/0057166, discloses a method for detecting and mitigating advanced persistent threats.
Manadhata et al, US Patent Application Publication 2017/0070518, discloses methods for identifying advanced persistent threats.
Singh et al, US Patent Application Publication 2017/0223037, discloses methods for analyzing suspect network traffic to detect threats.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Zachary A Davis whose telephone number is (571)272-3870. The examiner can normally be reached Monday-Friday, 9:00am-5:30pm, Eastern Time.
Examiner interviews are available via telephone and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Rupal D Dharia can be reached at (571) 272-3880. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Zachary A. Davis/Primary Examiner, Art Unit 2492