Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 21,23-25,27,29,31-33,35,37-38,44,45 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The claim(s) recite(s) mental processes – concepts performed in the human mind.
Regarding claim 21, with the exception of the recitation of the limitation ‘a computing platform communicatively coupled to a plurality of network nodes; the computing platform including a hardware processor and a system memory storing a software code; the hardware processor configured to execute the software code’, the claim recites mental processes concepts performed in the human mind. The limitations ‘detect a plurality of anomalous performance indicators originating from one or more of the plurality of network nodes; determine, based on a progressively cumulative score of the plurality of anomalous performance indicators characterizing the computer network incident, as the computer network evolves, a signature of the incident; compare the signature to at least one of a plurality of entries in an incident signature database; perform, when comparing determines that the signature corresponds to one or more of the plurality of entries, a root cause analysis of the incident using the corresponding one or more of the plurality of entries’ are mental processes concepts performed in the human mind by observation, evaluation, judgment, and/or opinion.
Step 2A: Prong two
This judicial exception is not integrated into a practical application because the additional elements ‘generate an incident alert including at least one of a result of the root cause analysis or a description of the incident; and display the incident alert using an incident identification pane, and a root cause analysis pane showing similarities between the incident and a plurality of root causes, the incident identification pane configured to enable a system user to select filtering criteria for displaying anomalous performance indicators based on the respective score assigned to each of the plurality of anomalous performance indicators’ are merely adding insignificant extra-solution activity to the judicial exception (MPEP 2105.05(g)).
Step 2B
The claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the additional elements ‘a computing platform communicatively coupled to a plurality of network nodes; the computing platform including a hardware processor and a system memory storing a software code; the hardware processor configured to execute the software code; determine, using the plurality of anomalous performance indicators in an automated process, an occurrence of an incident, wherein the occurrence of the incident is determined based on how many anomalous performance indicators are detected and a respective score assigned to each anomalous indicator based on a deviation of each anomalous indicator from a respective behavior defined as being normal for that anomalous indicator; infer, using a machine learning predictive model and based on the result of the root cause analysis, a solution for performing at least one of a mitigation or a resolution of the incident; via a communication network; via the communication network to at least one of the one or more of the plurality of network nodes’ is directed to generic computer components recited at a high-level of generality such that they amount to nothing more than mere instructions to apply the exception using generic computer components (MPEP 2106.05(f)). The machine learning predictive model is described at a high level such that it amounts to using a computer with a generic machine learning predictive model with only stating that the machine learning predictive model is used to detect anomalies.
The claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the additional elements ‘execute, during the incident, the inferred solution to mitigate or resolve the incident’ is simply appending well-understood, routine, conventional activities previously known to the industry, specified at a high-level of generality to the judicial exception (MPEP 2106.05(d)). The USPN 7120633 discloses in column 1, lines 56-59 - As one skilled in the art will recognize, various well-known methods and systems exist for executing such corrective actions and USPN 8620921 discloses in column 2, lines 48 -52 - As known in the art, the MAPE procedure will constantly monitor (M) each SLO and workload to determine any SLO violations, and if so, will analyze (A) and plan (P) multiple proposed solutions to help in selecting a particular solution, and then execute (E) the selected solution.
The claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the additional elements ‘wherein executing the inferred solution includes outputting one or more instructions for mitigating or resolving the incident’ is simply appending well-understood, routine, conventional activities previously known to the industry, specified at a high-level of generality to the judicial exception (MPEP 2106.05(d)). USPN 20070220303A1 – discloses in a conventional network management, a countermeasure method in the case where a failure has occurred in a network has been such that a highly skilled operator directly deals with each failure, or that operating methods for recovering the network from simple failures are prepared as a script on a computer beforehand, whereupon an operator selects the corresponding operating method., in paragraph 0004. USPN 20190258948A1 – discloses conventional automated help programs provide the same instructions for troubleshooting to every user, making no differentiation based on experience, skill level, and other profile attributes. These conventional programs also do not differentiate based on what has worked or not worked for users with different experience, skill levels, and other profile attributes., in paragraph 0027.
Regarding claim 23, the limitation ‘the plurality of anomalous performance indicators are detected during a time interval, and wherein the plurality of anomalous performance indicators are identified as anomalous based on a comparison of respectively corresponding performance indicators during a previous time interval’ is a mental process - concept performed in the human mind by observation, evaluation, judgment, and/or opinion.
Regarding claim 24, the limitation ‘the time interval extends from a first time of day to a second time of day, and wherein the previous time interval extends from the first time of day to the second time of day on a previous day’ is a mental process - concept performed in the human mind by observation, evaluation, judgment, and/or opinion.
Regarding claim 25, the limitation ‘the comparison is performed based on a Holt-Winters method’ is a mathematical concept per the specification.
Regarding claim 27, the limitation ‘the occurrence of the incident is determined using a principal component analysis’ is a mathematical concept per the specification.
Regarding claim 29, with the exception of the recitation of the limitation ‘a computing platform communicatively coupled to a plurality of network nodes; the computing platform including a hardware processor and a system memory storing a software code; the hardware processor configured to execute the software code’, the claim recites mental processes concepts performed in the human mind. The limitations ‘detecting a plurality of anomalous performance indicators originating from one or more of the plurality of network nodes; determining, based on a progressively cumulative score of the plurality of anomalous performance indicators characterizing the computer network incident, as the computer network evolves, a signature of the computer network incident; comparing the signature to at least one of a plurality of entries in an incident signature database; performing, when comparing determines that the signature corresponds to one or more of the plurality of entries, a root cause analysis of the incident using the corresponding one or more of the plurality of entries’ are mental processes concepts performed in the human mind by observation, evaluation, judgment, and/or opinion.
Step 2A: Prong two
This judicial exception is not integrated into a practical application because the additional elements ‘generating an incident alert including at least one of a result of the root cause analysis or a description of the incident; and displaying the incident alert using an incident identification pane, and a root cause analysis pane showing similarities between the incident and a plurality of root causes, the incident identification pane configured to enable a system user to select filtering criteria for displaying anomalous performance indicators based on the respective score assigned to each of the plurality of anomalous performance indicators’ are merely adding insignificant extra-solution activity to the judicial exception (MPEP 2105.05(g)).
Step 2B
The claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the additional elements ‘a computing platform communicatively coupled to a plurality of network nodes; the computing platform including a hardware processor and a system memory storing a software code; the hardware processor configured to execute the software code; determining, using the plurality of anomalous performance indicators in an automated process, an occurrence of an incident, wherein the occurrence of the incident is determined based on how many anomalous performance indicators are detected and a respective score assigned to each anomalous indicator based on a deviation of each anomalous indicator from a respective behavior defined as being normal for that anomalous indicator;; inferring, using a machine learning predictive model and based on the result of the root cause analysis, a solution for performing at least one of a mitigation or a resolution of the incident; via a communication network; via the communication network to at least one of the one or more of the plurality of network nodes’ is directed to generic computer components recited at a high-level of generality such that they amount to nothing more than mere instructions to apply the exception using generic computer components (MPEP 2106.05(f)). The machine learning predictive model is described at a high level such that it amounts to using a computer with a generic machine learning predictive model with only stating that the machine learning predictive model is used to detect anomalies.
The claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the additional elements ‘executing, during the incident, the inferred solution to mitigate or resolve the incident’ is simply appending well-understood, routine, conventional activities previously known to the industry, specified at a high-level of generality to the judicial exception (MPEP 2106.05(d)). The USPN 7120633 discloses in column 1, lines 56-59 - As one skilled in the art will recognize, various well-known methods and systems exist for executing such corrective actions and USPN 8620921 discloses in column 2, lines 48 -52 - As known in the art, the MAPE procedure will constantly monitor (M) each SLO and workload to determine any SLO violations, and if so, will analyze (A) and plan (P) multiple proposed solutions to help in selecting a particular solution, and then execute (E) the selected solution.
The claim(s) does/do not include additional elements that are sufficient to amount to significantly more than the judicial exception because the additional elements ‘wherein executing the inferred solution includes outputting one or more instructions for mitigating or resolving the incident’ is simply appending well-understood, routine, conventional activities previously known to the industry, specified at a high-level of generality to the judicial exception (MPEP 2106.05(d)). USPN 20070220303A1 – discloses in a conventional network management, a countermeasure method in the case where a failure has occurred in a network has been such that a highly skilled operator directly deals with each failure, or that operating methods for recovering the network from simple failures are prepared as a script on a computer beforehand, whereupon an operator selects the corresponding operating method., in paragraph 0004. USPN 20190258948A1 – discloses conventional automated help programs provide the same instructions for troubleshooting to every user, making no differentiation based on experience, skill level, and other profile attributes. These conventional programs also do not differentiate based on what has worked or not worked for users with different experience, skill levels, and other profile attributes., in paragraph 0027.
Regarding claim 31, the limitation ‘wherein the plurality of anomalous performance indicators are detected during a time interval, and wherein the plurality of anomalous performance indicators are identified as anomalous based on a comparison of respectively corresponding performance indicators during a previous time interval’ is a mental process - concept performed in the human mind by observation, evaluation, judgment, and/or opinion.
Regarding claim 32, the limitation ‘wherein the time interval extends from a first time of day to a second time of day, and wherein the previous time interval extends from the first time of day to the second time of day on a previous day’ is a mental process - concept performed in the human mind by observation, evaluation, judgment, and/or opinion.
Regarding claim 33, the limitation ‘the comparison is performed based on a Holt-Winters method’ is a mathematical concept per the specification.
Regarding claim 35, the limitation ‘the occurrence of the incident is determined using a principal component analysis’ is a mathematical concept per the specification.
Regarding claim 37, the limitations ‘the machine learning predictive model includes a plurality of parameters calculated using training data, the plurality of parameters defining a shape of the machine learning predictive model, wherein detecting the plurality of anomalous performance indicators is performed using the machine learning predictive model, the plurality of anomalous performance indicators being included in performance data originating from the one or more of the plurality of network nodes, and wherein the hardware processor is further configured to execute the software code to: retrain the machine learning predictive model using the performance data including the plurality of anomalous performance indicators to update the plurality of parameters; and detect, using the machine learning predictive model having the updated plurality of parameters, additional plurality of anomalous performance indicators in the additional performance data originating from the one or more of the plurality of network nodes’ is directed to generic computer components recited at a high-level of generality such that they amount to nothing more than mere instructions to apply the exception using generic computer components (MPEP 2106.05(f)). The machine learning predictive model is described at a high level such that it amounts to using a computer with a generic machine learning predictive model with only stating that the machine learning predictive model is used to detect anomalies and also mathematical concepts are involved in the parameter being calculated per the specification.
The limitation ‘receive additional performance data originating from the one or more of the plurality of network nodes’ is merely adding insignificant extra-solution activity to the judicial exception (MPEP 2105.05(g)), in this case data gathering.
Regarding claim 38, the limitations ‘the machine learning predictive model includes a plurality of parameters calculated using training data, the plurality of parameters defining a shape of the machine learning predictive model, wherein detecting the plurality of anomalous performance indicators is performed using the machine learning predictive model, the plurality of anomalous performance indicators being included in performance data originating from the one or more of the plurality of network nodes, and wherein the hardware processor is further configured to execute the software code to: retrain the machine learning predictive model using the performance data including the plurality of anomalous performance indicators to update the plurality of parameters; and detect, using the machine learning predictive model having the updated plurality of parameters, additional plurality of anomalous performance indicators in the additional performance data originating from the one or more of the plurality of network nodes’ is directed to generic computer components recited at a high-level of generality such that they amount to nothing more than mere instructions to apply the exception using generic computer components (MPEP 2106.05(f)). The machine learning predictive model is described at a high level such that it amounts to using a computer with a generic machine learning predictive model with only stating that the machine learning predictive model is used to detect anomalies and also mathematical concepts are involved in the parameter being calculated per the specification.
The limitation ‘receive additional performance data originating from the one or more of the plurality of network nodes’ are merely adding insignificant extra-solution activity to the judicial exception (MPEP 2105.05(g)), in this case data gathering.
Regarding claim 44, the limitations ‘generate a computer network incident alert in response to the computer network incident; and display, in real-time with respect to the occurrence of the computer network incident, an incident identification pane showing similarities between the computer network incident and a plurality of root causes, the incident identification pane configured to enable a system user to select filtering criteria for displaying anomalous performance indicators based on the respective score assigned to each of the plurality of anomalous performance indicators’ are merely adding insignificant extra-solution activity to the judicial exception (MPEP 2105.05(g)).
Regarding claim 45, the limitations ‘generating a computer network incident alert in response to the computer network incident; and displaying, in real-time with respect to the occurrence of the computer network incident, an incident identification pane showing similarities between the computer network incident and a plurality of root causes, the incident identification pane configured to enable a system user to select filtering criteria for displaying anomalous performance indicators based on the respective score assigned to each of the plurality of anomalous performance indicators’ are merely adding insignificant extra-solution activity to the judicial exception (MPEP 2105.05(g)).
Response to Arguments
Applicant's amendments and arguments filed 06/09/2026 have been fully considered. Claims 44 and 45 have now been examined properly for 101. The claims submitted on 10/01/2025 were not viewable in their normal state within the software that visually shows the application so the newly added claims 44 and 45 were missed.
The 101 rejection still stands. Concerning Applicant’s argument of the 101 rejection, the subject matter disclosed in the claim limitations are directed to an abstract idea. A human can in real-time compute deviation-based scores, maintain a progressively cumulative score of anomalous indicators characterizing a computer network incident, and determine an incident signature based on the cumulative score in the human mind and with the aid of a computer used as a tool. The reference to Micro, Inc. v. Bandai Namco Games Am., Inc. has been considered; however, the Micro Inc. case pertains to animation and not processing data for analysis for errors. The act of using cumulative scores and determining an incident signature have not been explained in any degree of detail that would prevent these acts from being performed in the human mind. The reference to the SRI Int’l, Inc. v. Cisco Syst., Inc. has been considered; however, as cited in the SRI Int’l, Inc. case ‘Indeed, representative claim 1 recites using network monitors to detect suspicious network activity based on analysis of network traffic data, generating reports of that suspicious activity, and integrating those reports using hierarchical monitors.’. The network traffic data was disclosed in the claim to be various types and in combination with generating reports and integrating those reports using hierarchical monitors that is bolstered by the specification were found to be an improvement in technology. The present claims are just generically processing network incidents, determining a cumulative scores, determining a signature based on the cumulative score, comparing signatures, generically using a machine learning predictive model based on root cause analysis to determine a solution, then execute the solution. The reference to Examiner 47 have been considered; however, they are not persuasive. The use of a machine learning predictive model in the claims is merely using a generic machine learning predictive model to perform an action.
The computing platform itself consists of generic computer components performing generic operations because there is no indication of how the scoring is performing and the other steps are plainly generic determining, comparing and performing steps. The well-understood, routine, conventional references are used to indicate the particular limitations are well-known to be performed. Published patent applications were presented for evidentiary support.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Yolanda L Wilson whose telephone number is (571)272-3653. The examiner can normally be reached M-F (7:30 am - 4 pm).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Bryce Bonzo can be reached on 571-272-3655. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Yolanda L Wilson/Primary Examiner, Art Unit 2113