DETAILED ACTION
In a communication received on 3 July 2026, amended claims 1, 9, 16 and 17.
Claims 1, 4-9 and 12-18 are pending.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
Applicant’s arguments with respect to claim(s) 1, 9, 16 and 17 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
With respect to claim 1, the applicants allege, "neither reference teaches or suggests that darknet monitoring is initiated or performed as a consequence of modifying a flag and a type in a socket buff er and a routing entry corresponding to packets destined for dark IP addresses" (page 16-17) with respect to the claimed limitation(s), "a flag and type modifying module configured to: modify, in a socket buffer, at least one of a flag to a local flag and a type to a local type corresponding to the received one or more TCP packets, when each of the one or more TCP packets is determined to be destined for each of one or more dark IP addresses; modify at least one of the flag to the local flag and the type to the local type corresponding to a routing entry associated with the socket buff er in a packet header corresponding to the one or more TCP packets, when the one or more TCP packets is determined to be destined for the one or more dark IP addresses; a darknet monitoring module configured to perform kernel-level active darknet monitoring of the one or more TCP packets destined to the one or more dark IP addresses based on the modifying of at least one of the flag to the local flag and the type to the local type in the socket buffer and the routing entry;". The examiner respectfully traverses. The arguments/remarks pertain to whether the cited prior art does not disclose flag/type modification and kernel-level darknet monitoring. The examiner concludes that the cited prior art clearly discloses or suggests the kernel level darknet monitoring by applying socket-buffer and packet header treatment with intercepted dark-address traffic along with active monitoring
"The test for obviousness is not whether the features of a secondary reference may be bodily incorporated into the structure of the primary reference.... Rather, the test is what the combined teachings of those references would have suggested to those of ordinary skill in the art." In re Keller, 642 F.2d 413, 425, 208 USPQ 871, 881 (CCPA 1981).
As best understood by the examiner, the claimed limitations broadly pertain to reading packet metadata for controlling and forwarding. Vissamsetty teaches deception server intercepting packets by redirecting with NAT to a deception interaction server (¶0053); and after engaging further monitoring attacker activity (¶0063). Xu discloses setting hardware NAT status flags for performing or skipping NAT processing (¶0062); and operation code and interface metadata in packet headers which can identify the local (¶0092). Therefore, Xu's socket-buffer and packet-header treatment can be applied to Vissamsetty's intercepted dark address traffic to provide local treatment and kernel processing for active monitoring.
In conclusion, the applicants argue(s) that the cited prior art does not disclose flag/type modification and kernel-level darknet monitoring. The examiner traverses because the cited prior art clearly discloses or suggests the kernel level darknet monitoring by applying socket-buffer and packet header treatment with intercepted dark-address traffic along with active monitoring.
The applicants allege, "Vissamsetty neither discloses nor suggests retrieval of a default outbound interface IP address, creation of a socket corresponding thereto, or transmission of a SYN-ACK packet through such a socket" (page 20) with respect to the claimed limitation(s), "an outbound interface address retrieving module configured to retrieve outbound interface IP addresses by circumnavigating a hash value comparison of network interface IP addresses with destination IP addresses assigned in the one or more TCP packets, wherein the retrieved outbound interface IP address is a default outbound interface IP address ; a socket creating module configured to create a socket corresponding to the retrieved default outbound interface IP addresses for transmitting a synchronization acknowledgement (SYN ACK) packet corresponding to the one or more TCP packets, based on the circumnavigation ; a packet outputting module configured to output the SYN-ACK packet to the one or more initiator devices, wherein the one or more initiator devices establish the communication channel by transmitting an acknowledgement (ACK) packet to the system, to establish a three-way handshake". The examiner respectfully traverses. The arguments/remarks pertain to whether the cited prior art does not disclose or suggest default outbound interface, socket creation, SYN-ACK output for three-way handshake. The examiner concludes that the cited prior art discloses or suggests output interface handling and engagement by Antoine's default route fallback, Xu's output-interface handling and Vissamsetty's SYN-ACK synonymous with three-way handshake for TCP-response
"The test for obviousness is not whether the features of a secondary reference may be bodily incorporated into the structure of the primary reference.... Rather, the test is what the combined teachings of those references would have suggested to those of ordinary skill in the art." In re Keller, 642 F.2d 413, 425, 208 USPQ 871, 881 (CCPA 1981).
As best understood by the examiner, the broadest reasonable interpretation of the claimed limitations reads on using a default outbound interface as a fallback when a match is not found.
Xu discloses fastNAT stores output interface information and performs routing to layer-three output interface bypassing the normal OS kernel net filter (¶0089-¶0090).
Antoine discloses forwards a packet along a default route when address correlation does not select a path, the default route used when forwarding route lookup fails (¶0023, ¶0037).
Vissamsetty discloses TCP proxy receiving SYN to an unassigned IP and generating SYN-ACK and performance of Three-Way Handshake (¶0032-0035, ¶0046). The Xu, Antoine, Vissamsetty combine to retrieving and using default outbound interface and sending a SYN-ACK through that interface.
In conclusion, the applicants argue(s) that the cited prior art does not disclose or suggest default outbound interface, socket creation, SYN-ACK output for three-way handshake. The examiner traverses because the cited prior art discloses or suggests output interface handling and engagement by Antoine's default route fallback, Xu's output-interface handling and Vissamsetty's SYN-ACK synonymous with three-way handshake for TCP-response.
The applicants allege, "Sutton does not disclose segregating backscattered traffic of a SYN-ACK packet from traffic associated with an active attacker based on engagement of the initiator device through a kernel-level active darknet monitoring mechanism" (page 21) with respect to the claimed limitation(s), "a traffic segregating module configured to segregate a backscattered traffic of the SYN-ACK packet and an active attacker in the one or more initiator devices". The examiner respectfully traverses. The arguments/remarks pertain to whether the cited prior art does not disclose or suggest segregating backscattered traffic from active attacker. The examiner concludes that the cited prior art clearly discloses or suggests the distinction of backscatter from active malicious attacks
Ascertaining the differences between the prior art and the claims at issue requires interpreting the claim language, and considering both the invention and the prior art references as a whole (See 2141.02 "Differences Between Prior art and Claimed Invention).
As best understood by the examiner, the broadest reasonable interpretation of the claimed limitations read on distinguishing backscatter traffic from active attacker traffic. Sutton discloses darknet traffic include spoof attacks and malicious scanning and distinguishes backscatter as communications not requiring establishment of a reliable connection (col. 1 lines 37-67). Vissamsetty discloses responding to SYN and SYN-ACK and initiation of TCP three-way handshake for the purpose of engaging (¶0032-¶0035). In combination, the art discloses or suggests that completion and noncompletion of the handshake predicts and distinguishes active initiators from backscatter.
In conclusion, the applicants argue(s) that the cited prior art does not disclose or suggest segregating backscattered traffic from active attacker. The examiner traverses because the cited prior art clearly discloses or suggests the distinction of backscatter from active malicious attacks.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1, 9, 17, and 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Vissamsetty et al. (US 2017/0331856 A1) in view of Sutton (US 8,413,238 B1) and Xu et al. (WO 2013/063791 A1), and further in view of Antoine et al. (US 2003/0009585 A1).
With respect to claim 1, Vissamsetty discloses: a computer-implemented system for kernel-level active darknet monitoring in a communication network, the computer-implemented system comprising: one or more hardware processors; a memory coupled to the one or more hardware processor, wherein the memory comprises a plurality of modules in form of programmable instructions executable by the one or more hardware processors (i.e., computing device including processors, memory, for executing instructions in Vissamsetty, ¶0074),
wherein the plurality of modules comprises: a packet receiving module configured to receive one or more transmission control protocol (TCP) packets from one or more initiator devices, wherein the one or more TCP packets comprises a synchronize packet (TCP-SYN) to initiate a connection with the system and establish a communication channel, wherein the one or more TCP packets are part of a network traffic comprising at least one of an Address Resolution Protocol (ARP), an Internet Protocol (IP), a Transmission Control Protocol (TCP), and an Internet Control Message Protocol (ICMP) (i.e., management server receives packets to an IP address including receiving a TCP SYN packet; the network traffic is at least comprising IP traffic and TCP handshake traffic in Vissamsetty, ¶0032, ¶0034),
a packet outputting module configured to output the SYN-ACK packet to the one or more initiator devices, wherein the one or more initiator devices establish the communication channel by transmitting an acknowledgement (ACK) packet to the system, to establish a three-way handshake (i.e., transmitting ACK and SYN-ACK packets to perform the 3-way handshake and establish it in Vissamsetty, ¶0032-0035, ¶0046).
Vissamsetty discloses IP addresses corresponding to the deception server, ¶0034, addresses won't be assigned to a VM, ¶0052, intercepting packets for the acquired IP addresses, ¶0053, the IP addresses routed to the deception server, ¶0063 (¶0034, ¶0052, ¶0053, ¶0063). Vissamsetty do(es) not explicitly disclose the following. Sutton, in order to identify malicious activity and collect information on traffic destined for darknet (col. 1 lines 58-67), discloses:
a dark internet protocol (IP) address determining module configured to determine one or more dark internet protocol (IP) address in the received one or more TCP packets, by comparing a destination IP address of the received one or more TCP packets with a plurality of IP addresses stored in a dark IP pool (i.e., comparing the destination addresses to a list of darknet addresses in Sutton, col. 2 lines 7-20, col. 8 lines 50-67); and
a traffic segregating module configured to segregate a backscattered traffic of the SYN-ACK packet and an active attacker in the one or more initiator devices. (i.e., segregation of backscatter and active attacker traffic corresponds to whether three-way handshake is completed and a reliable communication channel is established; backscattered traffic is limited to attacks such as denial of service which would not require completing the handshake, whereas active scanning and malicious code traffic would complete the three-way handshake in Sutton, col. 1 line 37-67).
Based on Vissamsetty in view of Sutton, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Sutton to improve upon those of Vissamsetty in order to identify malicious activity and collect information on traffic destined for darknet.
Vissamsetty discloses intercepting packets and performing network address translation of the packet to direct towards a deception server (¶0052-0053). Vissamsetty and Sutton do(es) not explicitly disclose modifying socket buffer or routing entry. Xu, in order to provide offloading of packets to bypass OS kernel netfilter processes (¶0005-0009), discloses:
a flag and type modifying module configured to: modify, in a socket buffer, at least one of a flag to a local flag and a type to a local type corresponding to the received one or more TCP packets, when each of the one or more TCP packets is determined to be destined for each of one or more dark IP addresses (i.e., setting status flags on the socket buffer corresponding to performing NAT or whether packet is supported for NAT in Xu, ¶0062);
modify at least one of the flag to the local flag and the type to the local type corresponding to a routing entry associated with the socket buffer in a packet header corresponding to the one or more TCP packets, when the one or more TCP packets is determined to be destined for the one or more dark IP addresses (i.e., inserting additional bytes in packet header to provide an operation code or interface index that indicates direction source/destination of the packet in Xu, ¶0010, ¶0092).
Vissamsetty discloses monitoring the attacker actions and malicious code corresponding to intercepted packets (¶0064). Vissamsetty and Sutton do(es) not explicitly disclose modifying socket buffer or routing entry. Xu, in order to provide offloading of packets to bypass OS kernel netfilter processes (¶0005-0009), discloses:
a darknet monitoring module configured to perform kernel-level active darknet monitoring of the one or more TCP packets destined to the one or more dark IP addresses based on the modifying of at least one of the flag to the local flag and the type to the local type in the socket buffer and the routing entry (i.e., offloading NAT functionality from the OS kernel based on modification of packet header in Xu, ¶0008, ¶0092)
Vissamsetty discloses performing the three-way handshake where the TCP proxy generates SYN-ACK response (¶0034, ¶0046). Vissamsetty and Sutton do(es) not explicitly disclose create socket corresponding to outbound interface IP address. Xu, in order to provide offloading of packets to bypass OS kernel netfilter processes (¶0005-0009), discloses:
a socket creating module configured to create a socket corresponding to the retrieved default outbound interface IP addresses for transmitting a synchronization acknowledgement (SYN-ACK) packet corresponding to the one or more TCP packets, based on the circumnavigation (i.e., providing the packets corresponding to the offload hardware module to an Ethernet interface to transmit the ethernet packets; output interface information for forwarding packets through layer-3 interface in Xu, ¶0010, ¶0072, ¶0089, ¶0092).
Based on Vissamsetty in view of Sutton, and further in view of Xu, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Xu to improve upon those of Vissamsetty in order to provide offloading of packets to bypass OS kernel netfilter processes.
Vissamsetty discloses performing the three-way handshake where the TCP proxy generates SYN-ACK response (¶0034, ¶0046). Vissamsetty, Sutton, and Xu do(es) not explicitly disclose retrieving outbound IP address without comparison of interface and destination IP addresses. Antoine, in order to dynamic and reactive routing and forwarding protocols resilient to topology differences than static forwarding rules (¶0005-0009), discloses: an outbound interface address retrieving module configured to retrieve outbound interface IP addresses by circumnavigating a hash value comparison of network interface IP addresses with destination IP addresses assigned in the one or more TCP packets (i.e., routing switch forwards according to default route when other attempts to determine forwarding route fail; suggests alternate route to matching addresses in a database in Antoine, ¶0037),
wherein the retrieved outbound interface IP address is a default outbound interface IP address (i.e., a packet is forwarded along default route when an address is not correlated to an exterior path in Antoine, ¶0023, ¶0037).
Based on Vissamsetty in view of Sutton and Xu, and further in view of Antoine, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Antoine to improve upon those of Vissamsetty in order to dynamic and reactive routing and forwarding protocols resilient to topology differences than static forwarding rules.
With respect to claim 9, the limitation(s) of claim 9 are similar to those of claim(s) 1. Therefore, claim 9 is rejected with the same reasoning as claim(s) 1.
With respect to claim 17, the limitation(s) of claim 17 are similar to those of claim(s) 1 and 9. Therefore, claim 17 is rejected with the same reasoning as claim(s) 1 and 9.
With respect to claim 18, the limitation(s) of claim 18 are similar to those of claim(s) 2 and 10. Therefore, claim 18 is rejected with the same reasoning as claim(s) 1 and 9.
Claim(s) 4-7 and 12-15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Vissamsetty et al. (US 2017/0331856 A1) in view of Sutton (US 8,413,238 B1), Xu et al. (WO 2013/063791 A1), and Antoine et al. (US 2003/0009585 A1), and further in view of Sysman et al. (US 2017/0134423 A1).
With respect to claim 4, Vissamsetty discloses routing packets to designated IP addresses to engagement servers to monitor the attacker’s actions (¶0064). Vissamsetty, Sutton, Xu, and Antoine do(es) not explicitly disclose the following. Sysman, in order to entice attackers with a dynamic deception decoy endpoints to provide robust analysis of the attacker (¶0005-0009), discloses: the system of claim 1, wherein the plurality of modules further comprises:
an endpoint creating module configured to create one or more phantom responder endpoints to one or more attacks using the one or more dark IP addresses (i.e., directing a malicious attack to a dynamically created deception environment in Sysman, ¶0037);
a machine simulating module configured to simulate active machines corresponding to the active device for sending the response packets (i.e., dynamically created deception environment interacts with attacker in Sysman, ¶0034);
an activity deception module configured to perform deception of the one or more initiator devices performing a series of malicious operations in an attempt to compromise the one or more dark IP addresses, using the simulated active devices (i.e., interaction is deceptive, and access allowed to monitor the interaction with deception environment in Sysman, ¶0034, ¶0056); and
a data accumulating module configured to accumulate pre-determined threat intelligence data corresponding to the one or more attacks by the one or more initiator devices, and a modus operandi data corresponding to the one or more attacks. (i.e., learning from the activity pattern exhibited by the attackers’ interactions in Sysman, ¶0031-0032).
Based on Vissamsetty in view of Sutton, Xu, and Antoine, and further in view of Sysman, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Sysman to improve upon those of Vissamsetty in order to entice attackers with a dynamic deception decoy endpoints to provide robust analysis of the attacker.
With respect to claim 5, Vissamsetty discloses IP addresses corresponding to the deception server, ¶0034, addresses won't be assigned to a VM, ¶0052, intercepting packets for the acquired IP addresses, ¶0053, the IP addresses routed to the deception server, ¶0063 (¶0034, ¶0052, ¶0053, ¶0063). Vissamsetty do(es) not explicitly disclose the following. Sutton, in order to identify malicious activity and collect information on traffic destined for darknet (col. 1 lines 58-67), discloses:
the system of claim 4, wherein to accumulate the modus operandi data corresponding to the one or more attacks, the plurality of modules further comprises:
a data monitoring module configured to monitor packet capture (PCAP) data for determining one or more geo-locations of the one or more initiator devices (i.e., origin information including indicating that the source of attack may be within the enterprise network in Sutton, col. 12 lines 25-35 and 57-67);
a data analyzing module configured to analyze the data to identify attack patterns and a plurality of threat levels posed by the one or more initiator devices (i.e., referencing of master threat data to classify threats in Sutton, col. 7 lines 56-67); and
a report generating module configured to generate a modus operandi report corresponding to the identified attack patterns and the plurality of threat levels (i.e., notifying an administrator and indicating the specifics of malicious activity and involved devices in Sutton, col. 10 lines 60-67).
Based on Vissamsetty in view of Sutton, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Sutton to improve upon those of Vissamsetty in order to identify malicious activity and collect information on traffic destined for darknet.
With respect to claim 6, Vissamsetty discloses IP addresses corresponding to the deception server, ¶0034, addresses won't be assigned to a VM, ¶0052, intercepting packets for the acquired IP addresses, ¶0053, the IP addresses routed to the deception server, ¶0063 (¶0034, ¶0052, ¶0053, ¶0063). Vissamsetty do(es) not explicitly disclose the following. Sutton, in order to identify malicious activity and collect information on traffic destined for darknet (col. 1 lines 58-67), discloses:
the system of claim 1, wherein the plurality of modules further comprises:
a packet data accumulating module configured to accumulate PCAP data associated with the active device and the one or more initiator devices (i.e., logging node for storing data related to network traffic in Sutton, col. 4 lines 20-27);
a data analyzing module configured to analyze the accumulated PCAP data using a network security analyzing technique; (i.e., data inspection engines performing threat detection and classification in Sutton, col. 6 lines 3-17)
an alert generating module configured to generate one or more alerts using the network security analyzing technique, based on the analyzed PCAP data (i.e., notifying an administrator and indicating the specifics of malicious activity and involved devices in Sutton, col. 10 lines 60-67).
Based on Vissamsetty in view of Sutton, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Sutton to improve upon those of Vissamsetty in order to identify malicious activity and collect information on traffic destined for darknet.
Vissamsetty discloses routing packets to designated IP addresses to engagement servers to monitor the attacker’s actions (¶0064). Vissamsetty, Sutton, Xu, and Antoine do(es) not explicitly disclose the following. Sysman, in order to entice attackers with a dynamic deception decoy endpoints to provide robust analysis of the attacker (¶0005-0009), discloses: a prioritized alert determining module configured to determine one or more prioritized alerts in the generated one or more alerts, for the kernel-level active darknet monitoring (i.e., pushing log with varying levels of urgency in Sysman, ¶0181).
Based on Vissamsetty in view of Sutton, Xu, and Antoine, and further in view of Sysman, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Sysman to improve upon those of Vissamsetty in order to entice attackers with a dynamic deception decoy endpoints to provide robust analysis of the attacker.
With respect to claim 7, Vissamsetty discloses IP addresses corresponding to the deception server, ¶0034, addresses won't be assigned to a VM, ¶0052, intercepting packets for the acquired IP addresses, ¶0053, the IP addresses routed to the deception server, ¶0063 (¶0034, ¶0052, ¶0053, ¶0063). Vissamsetty do(es) not explicitly disclose the following. Sutton, in order to identify malicious activity and collect information on traffic destined for darknet (col. 1 lines 58-67), discloses:
the system of claim 6, wherein the PCAP data comprises information corresponding to at least one of network protocols, source IP addresses, destination IP addresses, outbound interface IP addresses, network interface IP addresses, port numbers, and payload of the one or more TCP packets (i.e., monitors communications for source and destination address to determine malicious activity related to darknet addresses in Sutton, col. 12 lines 25-35 and 57-67).
Based on Vissamsetty in view of Sutton, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Sutton to improve upon those of Vissamsetty in order to identify malicious activity and collect information on traffic destined for darknet.
With respect to claim 12, the limitation(s) of claim 12 are similar to those of claim(s) 4. Therefore, claim 12 is rejected with the same reasoning as claim(s) 4.
With respect to claim 13, the limitation(s) of claim 13 are similar to those of claim(s) 5. Therefore, claim 13 is rejected with the same reasoning as claim(s) 5.
With respect to claim 14, the limitation(s) of claim 14 are similar to those of claim(s) 6. Therefore, claim 14 is rejected with the same reasoning as claim(s) 6.
With respect to claim 15, the limitation(s) of claim 15 are similar to those of claim(s) 7. Therefore, claim 15 is rejected with the same reasoning as claim(s) 7.
Claim(s) 8 and 16 is/are rejected under 35 U.S.C. 103 as being unpatentable over Vissamsetty et al. (US 2017/0331856 A1) in view of Sutton (US 8,413,238 B1), Xu et al. (WO 2013/063791 A1), and Antoine et al. (US 2003/0009585 A1), and further in view of Tan et al. (US 2022/0210172 A1).
With respect to claim 8, Vissamsetty discloses IP addresses corresponding to the deception server, ¶0034, addresses won't be assigned to a VM, ¶0052, intercepting packets for the acquired IP addresses, ¶0053, the IP addresses routed to the deception server, ¶0063 (¶0034, ¶0052, ¶0053, ¶0063). Vissamsetty do(es) not explicitly disclose the following. Sutton, in order to identify malicious activity and collect information on traffic destined for darknet (col. 1 lines 58-67), discloses: the system of claim 1, wherein the plurality of modules further comprises: a warning generating module configured to generate one or more warnings corresponding to the profiled one or more attacks (i.e., notifying of potential malicious activity from the protected network provided by an authority node to an administrator of the enterprise in Sutton, col. 12 lines 57-67).
Based on Vissamsetty in view of Sutton, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Sutton to improve upon those of Vissamsetty in order to identify malicious activity and collect information on traffic destined for darknet.
Vissamsetty discloses intercepting packets and performing network address translation of the packet to direct towards a deception server (¶0052-0053). Vissamsetty, Sutton, Xu, and Antoine do(es) not explicitly disclose the following. Tan, in order to reduce false positives and therefore conserving system resources while still detecting attacks (col. 13 lines 5-11), discloses:
a geolocation mapping module configured to map one or more geolocations of the one or more initiator devices targeting the one or more dark IP addresses targeting one or more pre-defined ports associated with the active device (i.e., monitoring and tracking accesses of clients and determining their geolocation information based on IP address in Tan, ¶0021-¶0023);
an engage-time calculating module configured to calculate an average engagement time of the one or more initiator devices with each of the one or more pre-defined ports of the one or more dark IP addresses (i.e., determining a frequency of access suggesting a measurement of access times over a period of time in Tan, ¶0019-0020);
an attack determining module configured to determine the one or more attacks based on the calculated average engagement time of the one or more initiator devices with each of the one or more pre-defined ports of the one or more dark IP addresses (i.e., determining the service usage according to a time period and/or frequency range to indicate a malicious attack if above a threshold in Tan, ¶0036-0038);
an attacker profiling module configured to profile the one or more attacks from the one or more initiator devices based on determining the one or more attacks (i.e., determining malicious activity by client based on time/frequency of service usage and threshold distance to profile the client device accessing as an attacker in Tan, ¶0036-0038).
Based on Vissamsetty in view of Sutton, Xu, and Antoine, and further in view of Tan, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to utilize the teachings of Tan to improve upon those of Vissamsetty in order to reduce false positives and therefore conserving system resources while still detecting attacks.
With respect to claim 16, the limitation(s) of claim 16 are similar to those of claim(s) 8. Therefore, claim 16 is rejected with the same reasoning as claim(s) 8.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to SHERMAN L LIN whose telephone number is (571)270-7446. The examiner can normally be reached Monday through Friday 9:00 AM - 5:00 PM (Eastern).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Joon Hwang can be reached at 571-272-4036. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
Sherman Lin
9/19/2026
/S. L./Examiner, Art Unit 2447
/JOON H HWANG/Supervisory Patent Examiner, Art Unit 2447