DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statement (IDS) submitted on January 18, 2024 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claim 3 is rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention.
The term “same unique identifier” is a term with ambiguous language that renders the claim indefinite. The word “same” followed by “unique” creates an uncertainty in the metes and bounds of what is being claimed, as the words are mutually exclusive (a unique identifier cannot be shared by multiple instances). Additionally, the specification does not provide that clarifies this ambiguity.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract
idea without significantly more. Below is a claim-by-claim analysis.
Claim 1, 10, 19
Step 1: Recites a method (claim 1). Claims 10 and 19 cite one or more computer readable storage media
that are restricted from signals per se in the specification (see Paragraph 26). Therefore, they are all
directed to the statutory categories of invention.
Step 2A Prong 1: The claim recites:
Converting the system log information into sentences
The process of translating raw data into something with semantic meaning can be considered a mental process
Step 2A Prong 2: The judicial exception is not integrated into a practical application. The remaining
limitations of the claim are directed to insignificant extra-solution activity (“aggregating system log information”), or merely applying/generally linking the judicial exception (“training a foundation model…”, “augmenting the foundation model…”, “causing downstream application to be implemented using the foundation model”)
Step 2B: The claim does not contain significantly more than the judicial exception. The analysis mirrors
the analysis of step 2A prong 2.
Claim 2, 11, 20
Step 1: Recites a method (claim 2). Claims 11 and 20 cite one or more computer readable storage media
that are restricted from signals per se in the specification (see Paragraph 26). Therefore, they are all
directed to the statutory categories of invention.
Step 2A Prong 1: The claim recites the abstract idea it inherits from the claim it depends on. Additionally, it cites:
Creating groups of the sentences based at least in part on the similarity outputs
Categorizing outputs can be considered a mental process that can be done in one’s head
Generating similar pairs of the sentences by sampling the sentences from a same one of the groups
Grouping categorized outputs can be considered a mental process that can be done in one’s head
Generating dissimilar pairs of the sentences by sampling the sentences from different ones of the group
Grouping categorized can be considered a mental process that can be done in one’s head
Step 2A Prong 2: The judicial exception is not integrated into a practical application. The remaining
limitations of the claim are directed at additional components of the application of the abstract idea (“converting a set of similarity rules…”, “generating a plurality of similarity outputs by applying the similarity hash…”, “performing the Siamese augmentation…”)
Step 2B: The claim does not contain significantly more than the judicial exception. The analysis mirrors
the analysis of step 2A prong 2.
Claim 3, 12
Step 1: Recites a method (claim 3). Claim 12 cites one or more computer readable storage media
that are restricted from signals per se in the specification (see Paragraph 26). Therefore, they are all
directed to the statutory categories of invention.
Step 2A Prong 1: The claim recites the abstract idea it inherits from the claim it depends on. Additionally, it cites:
Identifying ones of the sentences having a same unique identifier
Categorizing outputs can be considered a mental process that can be done in one’s head
Assigning the identified ones of the sentences to a same one of the groups
Categorizing outputs can be considered a mental process that can be done in one’s head
Step 2A Prong 2: The judicial exception is not integrated into a practical application.
Step 2B: The claim does not contain significantly more than the judicial exception. The analysis mirrors
the analysis of step 2A prong 2.
Claim 4, 13
Step 1: Recites a method (claim 4). Claim 13 cites one or more computer readable storage media
that are restricted from signals per se in the specification (see Paragraph 26). Therefore, they are all
directed to the statutory categories of invention.
Step 2A Prong 1: The claim recites the abstract idea it inherits from the claim it depends on.
Step 2A Prong 2: The judicial exception is not integrated into a practical application. The remaining
limitations of the claim are directed at additional components of the application of the abstract idea (“wherein the generating similar pairs of the sentences includes, for each of the groups of sentences: combining the sentences in a given one of the groups into random pairs.”)
Step 2B: The claim does not contain significantly more than the judicial exception. The analysis mirrors
the analysis of step 2A prong 2.
Claim 5, 14
Step 1: Recites a method (claim 5). Claim 14 cites one or more computer readable storage media
that are restricted from signals per se in the specification (see Paragraph 26). Therefore, they are all
directed to the statutory categories of invention.
Step 2A Prong 1: The claim recites the abstract idea it inherits from the claim it depends on.
Step 2A Prong 2: The judicial exception is not integrated into a practical application. The remaining
limitations of the claim are directed at additional components of the application of the abstract idea (“wherein each of the sentences in the given one of the groups is only included in one of the combined random pairs.”)
Step 2B: The claim does not contain significantly more than the judicial exception. The analysis mirrors
the analysis of step 2A prong 2.
Claim 6, 15
Step 1: Recites a method (claim 6). Claim 15 cites one or more computer readable storage media
that are restricted from signals per se in the specification (see Paragraph 26). Therefore, they are all
directed to the statutory categories of invention.
Step 2A Prong 1: The claim recites the abstract idea it inherits from the claim it depends on. Additionally, it cites:
Sampling a predetermined number of the sentences from each group
Generically sampling from a set of choices can be considered a mental process that can be done in one’s head
Combining the sentences in a given one of the groups with a respective sentence in a different one of the groups
Generically combining abstract concepts can be considered a mental process that can be done in one’s head
Step 2A Prong 2: The judicial exception is not integrated into a practical application. There are no remaining limitations in the claim.
Step 2B: The claim does not contain significantly more than the judicial exception. The analysis mirrors
the analysis of step 2A prong 2.
Claim 7, 16
Step 1: Recites a method (claim 7). Claim 16 cites one or more computer readable storage media
that are restricted from signals per se in the specification (see Paragraph 26). Therefore, they are all
directed to the statutory categories of invention.
Step 2A Prong 1: The claim recites the abstract idea it inherits from the claim it depends on.
Step 2A Prong 2: The judicial exception is not integrated into a practical application. The remaining
limitations of the claim are directed at additional components of the application of the abstract idea (“wherein a number of the dissimilar pairs that are generated is greater than a number of the similar pairs generated.”)
Step 2B: The claim does not contain significantly more than the judicial exception. The analysis mirrors
the analysis of step 2A prong 2.
Claim 8, 17
Step 1: Recites a method (claim 8). Claim 17 cites one or more computer readable storage media
that are restricted from signals per se in the specification (see Paragraph 26). Therefore, they are all
directed to the statutory categories of invention.
Step 2A Prong 1: The claim recites the abstract idea it inherits from the claim it depends on.
Step 2A Prong 2: The judicial exception is not integrated into a practical application. The remaining
limitations of the claim are directed at generally linking the judicial exception to a particular technological environment or field of use (“wherein the downstream application is a cybersecurity application.”)
Step 2B: The claim does not contain significantly more than the judicial exception. The analysis mirrors
the analysis of step 2A prong 2.
Claim 9, 18
Step 1: Recites a method (claim 9). Claim 18 cites one or more computer readable storage media
that are restricted from signals per se in the specification (see Paragraph 26). Therefore, they are all
directed to the statutory categories of invention.
Step 2A Prong 1: The claim recites the abstract idea it inherits from the claim it depends on.
Step 2A Prong 2: The judicial exception is not integrated into a practical application. The remaining
limitations of the claim are additional components of the insignificant extra-solution activity (“wherein the system log information is received from a source selected from the group consisting….”)
Step 2B: The claim does not contain significantly more than the judicial exception. The analysis mirrors
the analysis of step 2A prong 2.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 8-10, 17-19 are rejected under 35 U.S.C. 103 as being unpatentable over Zhou et al. (“SITD: Insider Threat Detection Using Siamese Architecture on Imbalanced Data”, 2022), in view of Bhattacharya et al. (“An Online Parsing Framework for Semistructured Streaming System Logs of Internet of Things Systems”, 2022).
Regarding claim 1, Zhou teaches a computer-implement method comprising:
aggregating system log information (Page 248, Column 1, Paragraph 5, “The dataset simulates 18-month behavior logs (HTTP, logon, device, file, and email) of 2,000 users, where 99 are insiders under red team scenarios”)
training a foundation1 model (Page 247, Column 1, Paragraph 3, “…which consists of two identical CNN networks sharing parameters, as shown in Fig. 1. We choose CNN because it is a trainable, multi-layer, non-linear, and end-to-end network …” using…2 the system log information (Page 245, Column 2, Paragraph 2, “…we capture user activity and content information from user logs and represent them as images. In the training phase, we feed two images into the model as a pair of samples”)
augmenting the foundation model using Siamese augmentation (Page 247, Column 1, Paragraph 4, “We randomly extract a sample pair {(X1,y1),(X2,y2)} from the training set and let Y be a binary label of the pair. Y = 1 if y1 = y2 (a "similar pair") and Y = 0 otherwise (a "different pair"). The triplet (X1,X2,Y ) is fed into the siamese network to train the sample pair classification model by minimizing the improved contrastive loss function.”3)
tuning the foundation model for a downstream application (Figure 2-44)
causing the downstream application to be implemented using the foundation model (Page 245, Column 2, Paragraph 2, ‘this paper proposes a new Siamese-architecture5 Insider Threat Detection (SITD) method, which detects whether the sample pairs belong to the same category by mapping sample pairs into low-dimensional space for similarity comparison to detect insider threats.”)
Zhou fails to teach converting the system log information to sentences. However, Bhattacharya teaches converting the system log information (Table 1; Page 7, Column 1-2, “These log snippets are basically a set of unstructured log chunks and contain a series of nonwrangled text information that is unsuitable for data processing”) to sentences (Figure 66).
Zhou and Bhattacharya are considered analogous to the invention because all are directed to the use of system logs in machine learning contexts. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to have modified Zhou to incorporate the teachings of Bhattacharya, and include a means for processing raw log data to enhance its contextual information. Doing so makes for proactive approach prediciting log errors and failures (see Page 2, Column 1, Paragraph 5 of Bhattacharya).
Regarding claim 8, Zhou teaches wherein the downstream application is a cybersecurity application (Page 245, Abstract, “In the insider threat7 detection domain… This paper proposes a new Siamese-architecture Insider Threat Detection (SITD) method… significantly enhances the detection performance”)
Regarding claim 9, Zhou teaches the CIM as taught in claim 1, wherein the system log information is received from a source selected from the group consisting of: Security Incident and Event Management (SIEM) systems, computational devices, and operating systems (Page 248, Column 1, Paragraph 5, “The dataset simulates 18-month behavior logs (HTTP, logon, device, file, and email) of 2,000 users”)
Claim 10 is a computer program product claim corresponding to the method claim 1 and is rejected for the same reasons as given in the rejection of that claim.
Claim 17 is a computer program product claim corresponding to the method claim 9 and is rejected for the same reasons as given in the rejection of that claim.
Claim 18 is a computer program product claim corresponding to the method claim 9 and is rejected for the same reasons as given in the rejection of that claim.
Claim 19 is a system claim corresponding to the method claim 1 and is rejected for the same reasons as given in the rejection of that claim.
Claims 2-3, 11-12, 20 are rejected under 35 U.S.C. 103 as being unpatentable over Zhou et al. (“SITD: Insider Threat Detection Using Siamese Architecture on Imbalanced Data”, 2022), in view of Bhattacharya et al. (“An Online Parsing Framework for Semistructured Streaming System Logs of Internet of Things Systems”, 2022) and in further view of Wang et al. (“Hashing for Similarity Search: A Survey “) and Jose8 at al. (“Optimized Binary Hashing Codes Generated by Siamese Neural Networks for Image Retrieval”, 2018).
Regarding claim 2, Zhou teaches the computer-implemented method, as taught in claim 1, and the use of system log information (see claim 1 analysis). Zhou fails to teach:
converting a set of similarity rules corresponding to the system log information into a similarity hash function;
generating a plurality of similarity outputs by applying the similarity hash function to respective ones of the sentences;
creating groups of the sentences based at least in part on the similarity outputs;
generating similar pairs of the sentences by sampling the sentences from a same one of the groups;
generating dissimilar pairs of the sentences by sampling the sentences from different ones of the groups; and
performing the Siamese augmentation using the similar pairs and the dissimilar pairs.
However,
Bhattacharya discloses the use of sentences (see claim 1 analysis),
Wang teaches converting a set of similarity rules corresponding to the…[data]9 into a similarity hash function (Page 5, Column 2, Paragraph 3, “Semi-supervised LSH [45], [46], [66] first learns a Mahalanobis metric from the semi-supervised information and then form the hash function according to the pairwise similarity… where GTG = A and A is the learnt metric from the semi-supervised information.”), and
Jose 1 teaches:
generating a plurality of similarity outputs by applying the similarity function to the respective [images] …10 (Page 1487, Abstract, “The training architecture takes a pair of images as input. The loss function trains the network so that similar images are mapped to similar binary codes and dissimilar images to different binary codes.”).
creating groups of the… [images] based at least in part on the similarity outputs (Page 1488, Column 2, Paragraph 6, “For testing purposes we generate a matrix B containing one binary code for each class. These binary codes are the mean binary codes of all images for each class.”)
generating similar pairs of the … [images] by sampling the … [images] from a same one of the groups (Page 1487, Column 2, Paragraph 4, “These images are called anchor images. For each anchor image one image belonging to the same class (positive pair) … are selected”)
generating dissimilar pairs of the … [images] by sampling the … [images] from different ones of the groups (Page 1487, Column 2, Paragraph 4, “These images are called anchor images. For each anchor image one image belonging… to a different class (negative pair) is selected are selected”)
performing Siamese augmentation using the similar pairs and the dissimilar pairs (Page 1488, Column 1, Figure 1).
Zhou, Bhattacharya, Wang and Jose 1 are considered analogous to the invention because all are directed to the use of machine learning. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to have modified Zhou to incorporate the teachings of Wang and Jose 1, and include a means for hashing data based on similarity. Doing so makes for more efficient storage and retrieval (See Page 1487, Column 1 Paragraph 3 of Jose 1).
Regarding claim 3, Zhou teaches the computer-implemented method, as taught in claim 2, and the use of system log information (see claim 1 analysis). Zhou fails to teach identifying ones of the sentences having a same unique identifier and assigning the identified ones of the sentences to a same one of the groups.
However,
Bhattacharya discloses the use of sentences (see claim 1 analysis), and
Jose 1 teaches:
Identifying ones of the… [images] having a unique identifier11 (Page 1487, Abstract, “similar images are mapped to similar binary codes and dissimilar images”), and
Assigning the identified ones of the … [images] to a same one of the groups (Page 1488, Column 2, Paragraph 6, “we generate a matrix B containing one binary code for each class. These binary codes are the mean binary codes of all images for each class”)
Zhou, Bhattacharya, Wang and Jose 1 are considered analogous to the invention because all are directed to the use of machine learning. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to have modified Zhou to incorporate the teachings of Wang and Jose 1, and include a means for hashing data based on similarity. Doing so makes for more efficient storage and retrieval (See Page 1487, Column 1 Paragraph 3 of Jose 1).
Claim 11 is a computer program product claim corresponding to the method claim 2 and is rejected for the same reasons as given in the rejection of that claim.
Claim 12 is a computer program product claim corresponding to the method claim 3 and is rejected for the same reasons as given in the rejection of that claim.
Claim 20 is a system claim corresponding to the method claim 2 and is rejected for the same reasons as given in the rejection of that claim.
Claims 4, 13 are rejected under 35 U.S.C. 103 as being unpatentable over Zhou et al. (“SITD: Insider Threat Detection Using Siamese Architecture on Imbalanced Data”, 2022), in view of Bhattacharya et al. (“An Online Parsing Framework for Semistructured Streaming System Logs of Internet of Things Systems”, 2022), and in further view of Jose et al.12 (“Binary hashing using Siamese neural networks”, 2018).
Regarding claim 4, Zhou teaches the computer-implemented method, as taught in claim 1, and the use of system log information (see claim 1 analysis). Zhou fails to teach:
combining the sentences in a given one of the groups into random pairs.
However,
Bhattacharya discloses the use of sentences (see claim 1 analysis), and
Jose 2 teaches wherein the generating of the similar pairs of… [images] includes, for each of the groups of…[images] (Page 2918, Column 1, Algorithm 113):
Combining the… [images] in a given one of the groups into random pairs (Page 2918, Column 1, Paragraph 1, “The training for neural networks is done in mini-batches. In each mini-batch, similar and dissimilar pairs are generated. At first a random image (anchor image) is selected from the mini-batch. Now, the simplest idea for creating dissimilar pair might be to randomly choose an image with different label than the anchor image.”)
Zhou, Bhattacharya and Jose 2 are considered analogous to the invention because all are directed to the use of machine learning. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to have modified Zhou to incorporate the teachings of Jose 2, and include a means for hashing data based on similarity. Doing so makes for more efficient storage and retrieval (See Page 2916, Column 2, Paragraph 2 of Jose 2).
Claim 13 is a computer program product claim corresponding to the method claim 4 and is rejected for the same reasons as given in the rejection of that claim.
Claims 5-7, 14-16 are rejected under 35 U.S.C. 103 as being unpatentable over Zhou et al. (“SITD: Insider Threat Detection Using Siamese Architecture on Imbalanced Data”, 2022), in view of Bhattacharya et al. (“An Online Parsing Framework for Semistructured Streaming System Logs of Internet of Things Systems”, 2022), and in further view of Morge-Rollet et al. (“Siamese Network on I/Q Signal for RF Fingerprinting”, 2022) and Jose 2 et al. (“Binary hashing using Siamese neural networks”, 2018).
Regarding claim 5, Zhou teaches the computer-implemented method, as taught in claim 4, and the use of system log information (see claim 1 analysis). Zhou fails to teach wherein each of the sentences in the given one of the groups is only included in one of the combined random pairs.
However,
Bhattacharya discloses the use of sentences (see claim 1 analysis),
Jose 2 teaches the uses of randomness to create pairs (see claim 4 analysis), and
Morge-Rollet discloses wherein each of the … [datapoints] in the given one of the groups is only included in one of the combined … pairs (Page 4, Paragraph 2, “using a sampling without replacement14 to create the positive pairs and we choose N inputs with different class using a sampling without replacement to create negative pairs.”)
Zhou, Bhattacharya, Jose 2, and Morge-Rollet are considered analogous to the invention because all are directed to the use of machine learning. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to have modified Zhou to incorporate the teachings of Jose 2 and Morge-Rollet, and sample without replacement when making the pairs used for Siamese augmentation. Doing so better models the data to fit real world situations and circumstances (See Page 6, Paragraph 2 of Morge-Rollet).
Regarding claim 6, Zhou teaches the computer-implemented method, as taught in claim 4, and the use of system log information (see claim 1 analysis). Zhou fails to teach wherein the generating dissimilar pairs of the sentences includes:
sampling a predetermined number of the sentences from each of the groups; and
combining each of the sentences in a given one of the groups with a respective sentence in a different one of the groups.
However,
Bhattacharya discloses the use of sentences (see claim 1 analysis), and
Morge-Rollet discloses wherein the generating of dissimilar pairs… includes:
Sampling a predetermined number of the sentences from each of the groups (Page 7, Bullet Point 1, “The final implementation need at least one example per emitter15: one-shot learning”)
Combining each of the… [datapoints] in a given one of the groups with a respective … [datapoints] in a different one of the groups (see claim 5 analysis).
Zhou, Bhattacharya, Jose 2, and Morge-Rollet are considered analogous to the invention because all are directed to the use of machine learning. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to have modified Zhou to incorporate the teachings of Jose 2 and Morge-Rollet, and sample a predetermined number from each group when making dissimilar pairs. Doing so allows the network to better generalize the variability of data it encounters (See Page 7, Paragraph 1-2 of Morge-Rollet).
Regarding claim 7, Zhou teaches the computer-implemented method, as taught in claim 6, and the use of system log information (see claim 1 analysis). Zhou fails to teach wherein a number of the dissimilar pairs that are generated is greater than a number of the similar pairs that are generated.
However,
Bhattacharya discloses the use of sentences (see claim 1 analysis), and
Jose 2 discloses wherein the number of dissimilar pairs that are generated is greater than a number of the similar pairs that are generated (Page 2917, Column 2, Paragraph 3, “training data with C object classes with N images in each class can generate C × (N/2) similar pairs and NN × (C/2) dissimilar pairs”).
Zhou, Bhattacharya, and Jose 2 are considered analogous to the invention because all are directed to the use of machine learning. Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the invention to have modified Zhou to incorporate the teachings of Jose 2 and generate more dissimilar pairs than similar pairs. Doing so models the system closer to real world conditions.
Claim 14 is a computer program product claim corresponding to the method claim 5 and is rejected for the same reasons as given in the rejection of that claim.
Claim 15 is a computer program product claim corresponding to the method claim 6 and is rejected for the same reasons as given in the rejection of that claim.
Claim 16 is a computer program product claim corresponding to the method claim 7 and is rejected for the same reasons as given in the rejection of that claim.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MATTHEWOS MESFIN whose telephone number is (571)270-0782. The examiner can normally be reached Monday-Friday 8am-5pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Cesar Paula can be reached at (571) 272-4128. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MATTHEWOS MESFIN/Examiner, Art Unit 2145
/CESAR B PAULA/Supervisory Patent Examiner, Art Unit 2145
1 According to specification, “a “foundation model” is intended to refer to any artificial intelligence based model that is trained on a broad set of information such that it may be applied across a wide range of use cases, Paragraph 46
2 The use of sentences based on the system log is taught by Bhattacharya, found below
3 According to the specification, “…it follows that operation 310 includes augmenting the foundation model using Siamese augmentation. In other words, the foundation model is updated based on identified pairs of similar sentences as well as pairs of dissimilar sentences”, Paragraph 83. Updating occurs by adjusting to minimize loss.
4 Adjustments to the CNN in type and parameter (tuning), for the purpose of insider threat detection (downstream application)
5 The foundation model of the twin CNN architecture causes the detection of insider threat our downstream application
6 The result of the transformation of unstructured logs into contextually aware Subject-Verb-Object sets (i.e. a sentence). According to specification, “…converting the received system log information into a string of characters and/or values that express a contextual concept in the form of a sentence”, Paragraph 62
7 “The insider threat has become one of the biggest cyber security challenges”, Page 1 Column 1 Paragraph 1
8 To be referred to as “Jose 1”
9 “system log information” is omitted, as Wang teaches the use of generic data. That claim limitation, however, is present in Sun, and can be combined to cover the statement as a whole
10 “sentences” is omitted, as Jose 1 teaches the use of images. That claim limitation, however, is present in Bhattacharya, and can be combined to cover the statement as a whole. This applies to all future omissions of “sentences”
11 This claim limitation has a 112b rejection, and is being interpreted as “having a similar identifier”
12 To be referred to as “Jose 2”
13 Algorithm shows that the generation of pairs is done for each label (i.e. group)
14 “sampling without replacement” indicates that each datapoint is only included in one pair
15 Emitter is equivalent to class (i.e. group)