DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claims 1-22 are pending.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The text of those sections of Title 35, U.S. Code not included in this action can be found in a prior Office action.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
Claims 1-9, 13 and 22 are rejected under 35 U.S.C. 103 as being unpatentable over Abbaszadeh et al. (Abbaszadeh), US Patent Application Publication No. US 2020/0067969, and further in view of Melnykov et al. (Melnykov), “On model-based clustering of skewed matrix data”, available on line 26 April 2018, Journal of Multivariate Analysis 167 (2018), pages 181-194.
As to independent claim 1, Abbaszadeh discloses a method performed by at least one computer processor executing computer program instructions stored on at least one non-transitory computer-readable medium, the method comprising:
receiving multivariate feature data,
the multivariate feature data comprising a plurality of multivariate
feature vectors (Abstract: a plurality of monitoring nodes may each generate a time series of current monitoring node values representing current operation of a cyber-physical system, and a feature-based forecasting framework receive the time-series and generate a set of current feature vectors; paragraph [0103]: the time series may be modeled as a multivariate autoregressive model (VAR model)),
wherein each of the multivariate feature vectors comprises a corresponding
plurality of values of a plurality of features (Abstract and paragraphs [0037], [0043]: the system may retrieve, for each of a plurality of monitoring nodes, a series of normal values over time that represent normal operation of the cyber-physical system);
producing a plurality of clusters based on the multivariate feature data (Abstract: a set of ensemble state-space models may be constructed to represent feature evolution in the time-domain, wherein the forecasted outputs from the set of ensemble state-space models comprise anticipated time evolution of features);
and
assigning, for each the multivariate feature vectors V and for each of
the plurality of clusters C, a probability that vector V is within cluster C (paragraph [0034]: the ensembles may be selected using a soft cluster method, such as Gaussian Mixture Model (“GMM”) clustering, which may provide both centroid and probability membership functions; paragraph [0097]: the GMM clustering partitions the operating space (projected into feature space) into multiple clusters each represented by a multivariate Gaussian process described by a mean (centroid) and a covariance matrix. The centroid of each cluster represents the operating point for each ensemble model while its covariance matrix establishes a probabilistic membership function),
Abbaszadeh discloses that many different types of features may be utilized in principal components and statistical features, e.g., mean, variance, skewness, maximum, minimum values of time series signals (paragraph [0050]). Abbaszadeh, however, does not disclose wherein the assigning comprises assigning, to each of the plurality of clusters, a corresponding skew to account for skew in the plurality of
multivariate feature vectors.
In the same field of endeavor, Melnykov discloses on model-based clustering of skewed matrix data (Title). Melnykov further discloses in Abstract that the existing finite mixture modeling and model-based clustering literature focuses primarily on the analysis of multivariate data observed in the form of vectors, with each element representing a specific feature, and multivariate Gaussian mixture models have been the most commonly used. Melnykov further discloses in Abstract that targeting the problem of mixture modeling with components that can handle skewness in matrix-valued data. Melnykov further discloses in page 181, 1. Introduction: model-based clustering assumes that each cluster can be seen as a sample from an underlying mixture component, i.e., there exists a one-to-one correspondence between components and data groups. Melnykov further discloses in page 181, 1. Introduction: distributions capable of modeling various data shapes, especially skewness, wherein mixtures of multivariate skew-normal and skew-t distributions are the most popular choices. Melnykov further discloses in page 182: proposing a mixture model that relies on the novel class of matrix distributions that can model skewness effectively. Melnykov further discloses in page 183, 2.3. Matrix transformation mixture model: a novel matrix mixture model that is capable of modeling skewness effectively.
It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the system of Abbaszadeh to include wherein the assigning comprises assigning, to each of the plurality of clusters, a corresponding skew to account for skew in the plurality of multivariate feature vectors, as taught by Melnykov for the purpose of providing modeling skewness effectively.
As to dependent claim 2, Abbaszadeh discloses wherein clustering the plurality of features comprises clustering the plurality of features using Expectation Maximization of a Gaussian Mixture Model (GMM) (paragraph [0097]).
As to dependent claim 3, Abbaszadeh discloses wherein the number of the plurality of clusters is equal to the number of the plurality of features (paragraphs [0034], [0079]).
As to dependent claim 4, Abbaszadeh discloses wherein (C) comprises learning a multivariate model based on the plurality of features simultaneously (paragraph [0121]).
As to dependent claim 5, Abbaszadeh discloses wherein learning the multivariate model comprises learning the multivariate model based on the plurality of multivariate feature vectors (paragraph [0121]).
As to dependent claim 6, Abbaszadeh discloses wherein the multivariate model comprises a composition of a plurality of Gaussian distributions (paragraph [0096]).
As to dependent claim 7, Abbaszadeh discloses wherein the composition of the plurality of Gaussian distributions comprises a convolution of the plurality of Gaussian
Distributions (paragraphs [0079], [0096]).
As to dependent claim 8, Abbaszadeh discloses wherein each of the plurality of Gaussian distributions corresponds to a distinct one of the plurality of clusters (paragraph [0096]).
As to dependent claim 9, Abbaszadeh discloses further comprising, after (A), (B), and (C):
receiving a new multivariate feature vector that was not within the
multivariate feature data (Abstract; paragraph [0006]); and
determining, based on the learned model and the new multivariate
feature vector, whether the new multivariate feature vector represents an anomaly (Abstract; paragraph [0006]).
As to dependent claim 13, Abbaszadeh discloses wherein (E) comprises:
(E)(1) identifying, for each of the plurality of clusters in the learned model, a percentage likelihood that the new multivariate feature vector falls within that cluster (paragraphs [0080], [0090], [0099]); and
(E)(2) determining that the new multivariate feature vector is an anomaly if the new multivariate feature vector is determined not to fall within any of the plurality of clusters (paragraphs [0080], [0090], [0099], [0108]).
Claim 22 is system claim that contains similar limitations of claim 1. Therefore, claim 22 is rejected under the same rationale.
Claims 10-12 and 14-21 are rejected under 35 U.S.C. 103 as being unpatentable over Abbaszadeh and Melnykov as applied to claims 1-9, 13, and 22 above, and further in view of Dixit, US Patent Application Publication No. US 2022/0358212 A1.
As to dependent claim 10, Abbaszadeh and Melnykov, however, do not disclose discloses wherein (D) comprises:
(D)(1) detecting a user login access attempt; and
(D)(2) generating the new multivariate feature vector to represent a plurality of features of the user login access attempt; and
wherein (E) comprises determining, based on the learned model and the new
multivariate feature vector, whether the user login access attempt is an anomaly.
In the same field of endeavor, Dixit discloses in Abstract that the output of an autoencoder model is used to provide reasons for classifying logged event data as anomalous. Multivariate input feature vectors based on the event data are applied to the autoencoder model to generate corresponding predicted multivariate feature vectors with respective feature elements. Each feature element of each vector corresponds to a respective type of event data (e.g., sign-in failures). A reconstruction loss is determined for each predicted feature vector and used to classify the predicted feature vector as anomalous or not anomalous. Dixit further discloses in paragraph [0041] that data from sign-in logs may be aggregated by user ID to create per-user sessions, data from DNS logs maybe aggregated by IP address to create per-IP address session, and multivariate input feature vectors may be created for each session, where each feature element of an input feature vector may comprise a value associated with a type of event or activity. Dixit further discloses in paragraph [0062] that a plurality of multivariate test input feature vectors may be autoencoded based on a trained autoencoder model to generate a plurality of outputs. For example, in a manner similar as the method described above with respect to step 502 (FIG. 5), trained autoencoder model 322 may be configured to autoencode each of the plurality of test input feature vectors 316, where each feature element of each of the plurality of test input feature vectors 316 may correspond to a respective type of event data (e.g., a count of failed sign-in logs, a count of number of IP addresses signed in from, etc.).
It would have been obvious to one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify the systems of Abbaszadeh and Melnykov to include (D)(1) detecting a user login access attempt; and (D)(2) generating the new multivariate feature vector to represent a plurality of features of the user login access attempt; and wherein (E) comprises determining, based on the learned model and the new multivariate feature vector, whether the user login access attempt is an anomaly, as taught by Dixit for the purpose of providing reasons for classifying event data as anomalous.
As to dependent claim 11, Abbaszadeh does not disclose but Dixit discloses wherein the plurality of features includes a geolocation of the user login access attempt and a time of the user login access attempt (Dixit, paragraphs [0024]-[0025], [0034]).
As to dependent claim 12, Abbaszadeh does not disclose but Dixit discloses wherein the geolocation of the user login access attempt comprises a latitude of the user login access attempt and a longitude of the user login access attempt, and wherein the time of the user login access attempt comprises a day of the user login access attempt and a time epoch of the user login access attempt (Dixit, paragraphs [0024]-[0025], [0034], [0040]).
As to dependent claim 14, Abbaszadeh does not disclose but Dixit discloses wherein the plurality of features includes geolocation and access time of an attempted user login access attempt (Dixit, paragraph [0024]).
As to dependent claim 15, Abbaszadeh does not disclose but Dixit discloses wherein geolocation includes latitude and longitude (Dixit, paragraph [0034]).
As to dependent claim 16, Abbaszadeh does not disclose but Dixit discloses wherein access time includes time epoch and day (Dixit, paragraph [0041]).
As to dependent claim 17, Abbaszadeh does not disclose but Dixit discloses wherein the plurality of features includes a slow DNS tunnel feature (Dixit, paragraphs [0024], [0041]).
As to dependent claim 18, Abbaszadeh does not disclose but Dixit discloses wherein the plurality of features includes a fast DNS tunnel feature (Dixit, paragraphs [0024], [0041]).
As to dependent claim 19, Abbaszadeh does not disclose but Dixit discloses before (A): generating the multivariate feature data based on user login access data (Dixit, Abstract and paragraph [0036]).
As to dependent claim 20, Abbaszadeh does not disclose but Dixit discloses wherein the user login access data comprises a plurality of network flow logs (Dixit, paragraph [0023]).
As to dependent claim 21, Abbaszadeh does not disclose but Dixit discloses wherein the user login access data comprises a plurality of application logs (Dixit, paragraph [0023]).
Conclusion
Any inquiry concerning this communication should be directed to CHAU T NGUYEN at telephone number (571)272-4092. The examiner can normally be reached on M-F from 8am to 5pm (PT).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) Form at https://www.uspto.gov/patents/uspto-automated-interview-request-air-form.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Cesar Paula, can be reached at telephone number 5712724128. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from Patent Center and the Private Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from Patent Center or Private PAIR. Status information for unpublished applications is available through Patent Center and Private PAIR for authorized users only. Should you have questions about access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
/CHAU T NGUYEN/Primary Examiner, Art Unit 2145