Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Detailed Action
Claims filed on 06/29/2026 for patent application 18/421,600 have been acknowledged. Claims 1-20 are currently pending and have been considered below. Claims 1, 9, and 13 are independent claims. Claims 1-3, 9, 13-15, and 18-19 have been amended. No new claims have been added.
In view of amendments to claim 13, the 35 U.S.C. 101 rejection of 13-20 has been withdrawn.
Response to Arguments
Applicant’s arguments with respect to claims 1-20 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the arguments.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 6-13, and 18-20 are rejected under 35 U.S.C. 103 as being anticipated by Thakur et al. (US Patent Application Publication No. US 2022/0309157 A1, hereinafter, Thakur) in view of Mitra et al. (US Patent Application Publication No. US 2023/0177157 A1, hereinafter, Mitra).
Regarding Claim 1, Thakur discloses: A method of automatic remediation of a first missing or corrupted agent comprising (Thakur, ¶[0013], “it is recognized in the present Specification that interference with a system management agent or other critical process may itself be a reliable indicator of the presence of malware … Thus, if the system can be monitored, and attempts to disable or otherwise obstruct critical processes are detected, automated remediation can be initiated from a server.”):
detecting the first missing or corrupted agent installed on a first machine (Thakur, ¶[0065], “[0065] In block 410, an interface may be provided to register appropriate processes for monitoring. For example, vPro™ “agent presence” feature may be used to register one or more applications for monitoring.”),
determining a first service, that is associated with the first missing or corrupted agent, is non- operational (Thakur, ¶[0020], “… Intel® vPro™ provides (“out of the box”) a feature called “agent presence,” which can be configured to monitor a particular process, and report to an enterprise security controller if that process goes down.” ¶[0068] “In block 430, when any monitored process fails or is forcefully closed by a user or malicious app (optionally as determined by ESC 140), a remedial action may be taken.”), and
restarting the non-operational first service on the first machine, wherein the automatic remediation comprises restarting the non-operational first service on the first machine (Thakur, ¶[0013], “if the system can be monitored, and attempts to disable or otherwise obstruct critical processes are detected, automated remediation can be initiated from a server.”¶[0073], “e. If a monitored process is still not stabilizing, then apply the remediation action, including for example a process restart or applying System defense policy on the client.” ¶[0084-0089], “[0084] … remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0089] e. … remediating the system using a pre-defined cleaner/rescue image” ¶[0110] “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to restart a monitored process.”); and
reimaging the first machine, wherein the automatic remediation further comprises reimaging the first machine (Thakur, ¶[0084], “remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0087] c. Running diagnostic commands from the server to retrieve all events. [0088] d. Notifying security administrator 150 for issues with mission-critical services. [0089] e. If system is infected then remediating the system using a pre-defined cleaner/rescue image using integrated drive electronics (IDE)-redirection (IDER).” ¶[0112], “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to reimage the client device with a clean operating system image.”).
Thakur does not explicitly teach the following limitation that Mitra teaches:
for a detection count less than or equal to a threshold (Mitra, ¶[0075], “… then the timer 250 increases (340) a counter. If (350) the counter is less than a threshold … Otherwise, if (350) the counter is greater than a threshold, …”):
for the detection count greater than the threshold (Mitra, ¶[0075], “… then the timer 250 increases (340) a counter. If (350) the counter is less than a threshold … Otherwise, if (350) the counter is greater than a threshold, …”):
redetecting the first missing or corrupted agent installed on the first machine (Note: Thakur teaches “detecting the first missing or corrupted agent installed on a first machine,” while Mitra is only relied upon to teach “redetection.” Mitra, ¶[0075], “the detection engine 240 computes (320) a fingerprint for each incoming write 280 to the VM. … the detection engine 240 operates asynchronously with respect to the virtual machine.”), and
Thakur in view of Mitra is analogous art because the references are from the “same field of endeavor” and are from the same “problem solving area.” Namely, they pertain to the field of “remediation methods in cybersecurity.” It would have been obvious for one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Thakur with Mitra by implementing
“for a detection count less than or equal to a threshold:
for the detection count greater than the threshold:
redetecting the first missing or corrupted agent installed on the first machine”
Because remediation action can be taken based on a detection count compared to a threshold (Mitra, ¶[0065]).
Regarding Claim 6, Thakur in view of Mitra teaches: The method of claim 1, further comprising:
detecting a second missing or corrupted agent installed on a second machine (Thakur, ¶[0065], “[0065] In block 410, an interface may be provided to register appropriate processes for monitoring. For example, vPro™ “agent presence” feature may be used to register one or more applications for monitoring.”);
determining a second service associated with the second missing or corrupted agent is operational (Thakur, ¶[0020], “… Intel® vPro™ provides (“out of the box”) a feature called “agent presence,” which can be configured to monitor a particular process, and report to an enterprise security controller if that process goes down.” ¶[0068] “In block 430, when any monitored process fails or is forcefully closed by a user or malicious app (optionally as determined by ESC 140), a remedial action may be taken.”); and
reinstalling the second missing or corrupted agent on the second machine, wherein the automatic remediation further comprises reinstalling the second missing or corrupted agent on the second machine (Thakur, ¶[0013], “if the system can be monitored, and attempts to disable or otherwise obstruct critical processes are detected, automated remediation can be initiated from a server.” ¶[0073], “e. If a monitored process is still not stabilizing, then apply the remediation action, including for example a process restart or applying System defense policy on the client.” ¶[0084-0089], “[0084] … remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0089] e. … remediating the system using a pre-defined cleaner/rescue image.” ¶[0109], “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to reinstall a monitored application.”).
Regarding Claim 7, Thakur in view of Mitra teaches: The method of claim 6, further comprising:
redetecting the second missing or corrupted agent installed on the second machine (Thakur, ¶[0076-0083], “[0076] In block 480, … self-learning engine 326 may enter an unsupervised self-learning mode. [0077] In one or more embodiments, criteria to trigger a remediation process may include, by way of non-limiting example: [0078] a. Usage of high system resources compare to pre-defined consumption or previous usage pattern. [0079] b. Change of process identifier for a continuous running process. [0080] c. Removal/uninstallation of an application without removing the process monitoring from server. [0081] d. Interrupts and errors from a monitored process. [0082] e. Any system resource leak from a monitored process. [0083] f. Monitoring process is down or not sending heartbeat to agent presence monitor.”); and
reimaging the second machine, wherein the automatic remediation further comprises reimaging the second machine (Thakur, ¶[0084], “remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0087] c. Running diagnostic commands from the server to retrieve all events. [0088] d. Notifying security administrator 150 for issues with mission-critical services. [0089] e. If system is infected then remediating the system using a pre-defined cleaner/rescue image using integrated drive electronics (IDE)-redirection (IDER).” ¶[0112], “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to reimage the client device with a clean operating system image.”).
Regarding Claim 8, Thakur in view of Thakur teaches: The method of claim 1, wherein the first missing or corrupted agent comprises a first missing or corrupted security agent (Thakur, ¶[0017], “the enterprise security controller may be able to aggregate relevant and useful information to determine, for example, that a malware outbreak has occurred. For example, if a large number of hosts suddenly and near simultaneously lose their antivirus agents, then the enterprise security controller may determine that a malware outbreak is probably underway, and take appropriate remedial action.”).
Regarding Claim 9, Thakur discloses: A method of automatic remediation of a first missing or corrupted agent comprising (Thakur, ¶[0013], “it is recognized in the present Specification that interference with a system management agent or other critical process may itself be a reliable indicator of the presence of malware … Thus, if the system can be monitored, and attempts to disable or otherwise obstruct critical processes are detected, automated remediation can be initiated from a server.”):
detecting the first missing or corrupted agent installed on a first machine (Thakur, ¶[0065], “[0065] In block 410, an interface may be provided to register appropriate processes for monitoring. For example, vPro™ “agent presence” feature may be used to register one or more applications for monitoring.”),
determining a first service, that is associated with the first missing or corrupted agent, is operational (Thakur, ¶[0020], “… Intel® vPro™ provides (“out of the box”) a feature called “agent presence,” which can be configured to monitor a particular process, and report to an enterprise security controller if that process goes down.” ¶[0068] “In block 430, when any monitored process fails or is forcefully closed by a user or malicious app (optionally as determined by ESC 140), a remedial action may be taken.”), and
reinstalling the first missing or corrupted agent on the first machine, wherein the automatic remediation comprises reinstalling the first missing or corrupted agent on the first machine (Thakur, ¶[0013], “if the system can be monitored, and attempts to disable or otherwise obstruct critical processes are detected, automated remediation can be initiated from a server.” ¶[0073], “e. If a monitored process is still not stabilizing, then apply the remediation action, including for example a process restart or applying System defense policy on the client.” ¶[0084-0089], “[0084] … remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0089] e. … remediating the system using a pre-defined cleaner/rescue image.” ¶[0109], “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to reinstall a monitored application.”); and
reimaging the first machine, wherein the automatic remediation further comprises reimaging the first machine (Thakur, ¶[0084], “remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0087] c. Running diagnostic commands from the server to retrieve all events. [0088] d. Notifying security administrator 150 for issues with mission-critical services. [0089] e. If system is infected then remediating the system using a pre-defined cleaner/rescue image using integrated drive electronics (IDE)-redirection (IDER).” ¶[0112], “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to reimage the client device with a clean operating system image.”).
Thakur does not explicitly teach the following limitation that Mitra teaches:
for a detection count less than or equal to a threshold (Mitra, ¶[0075], “… then the timer 250 increases (340) a counter. If (350) the counter is less than a threshold … Otherwise, if (350) the counter is greater than a threshold, …”):
for the detection count greater than the threshold (Mitra, ¶[0075], “… then the timer 250 increases (340) a counter. If (350) the counter is less than a threshold … Otherwise, if (350) the counter is greater than a threshold, …”):
redetecting the first missing or corrupted agent installed on the first machine (Note: Thakur teaches “detecting the first missing or corrupted agent installed on a first machine,” while Mitra is only relied upon to teach “redetection.” Mitra, ¶[0075], “the detection engine 240 computes (320) a fingerprint for each incoming write 280 to the VM. … the detection engine 240 operates asynchronously with respect to the virtual machine.”), and
Thakur in view of Mitra is analogous art because the references are from the “same field of endeavor” and are from the same “problem solving area.” Namely, they pertain to the field of “remediation methods in cybersecurity.” It would have been obvious for one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Thakur with Mitra by implementing
“for a detection count less than or equal to a threshold:
for the detection count greater than the threshold:
redetecting the first missing or corrupted agent installed on the first machine”
Because remediation action can be taken based on a detection count compared to a threshold (Mitra, ¶[0065]).
Regarding Claim 10, Thakur in view of Mitra teaches: The method of claim 9, further comprising: detecting a second missing or corrupted agent installed on a second machine (Thakur, ¶[0065], “[0065] In block 410, an interface may be provided to register appropriate processes for monitoring. For example, vPro™ “agent presence” feature may be used to register one or more applications for monitoring.”);
determining a second service associated with the second missing or corrupted agent is non- operational (Thakur, ¶[0020], “… Intel® vPro™ provides (“out of the box”) a feature called “agent presence,” which can be configured to monitor a particular process, and report to an enterprise security controller if that process goes down.” ¶[0068] “In block 430, when any monitored process fails or is forcefully closed by a user or malicious app (optionally as determined by ESC 140), a remedial action may be taken.”); and
restarting the second service on the second machine, wherein the automatic remediation further comprises restarting the second service on the second machine (Thakur, ¶[0013], “if the system can be monitored, and attempts to disable or otherwise obstruct critical processes are detected, automated remediation can be initiated from a server.”¶[0073], “e. If a monitored process is still not stabilizing, then apply the remediation action, including for example a process restart or applying System defense policy on the client.” ¶[0084-0089], “[0084] … remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0089] e. … remediating the system using a pre-defined cleaner/rescue image” ¶[0110] “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to restart a monitored process.”).
Regarding Claim 11, Thakur in view of Mitra teaches: The method of claim 10, further comprising: redetecting the second missing or corrupted agent installed on the second machine (Thakur, ¶[0076-0083], “[0076] In block 480, … self-learning engine 326 may enter an unsupervised self-learning mode. [0077] In one or more embodiments, criteria to trigger a remediation process may include, by way of non-limiting example: [0078] a. Usage of high system resources compare to pre-defined consumption or previous usage pattern. [0079] b. Change of process identifier for a continuous running process. [0080] c. Removal/uninstallation of an application without removing the process monitoring from server. [0081] d. Interrupts and errors from a monitored process. [0082] e. Any system resource leak from a monitored process. [0083] f. Monitoring process is down or not sending heartbeat to agent presence monitor.”); and
reimaging the second machine, wherein the automatic remediation further comprises reimaging the second machine (Thakur, ¶[0084], “remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0087] c. Running diagnostic commands from the server to retrieve all events. [0088] d. Notifying security administrator 150 for issues with mission-critical services. [0089] e. If system is infected then remediating the system using a pre-defined cleaner/rescue image using integrated drive electronics (IDE)-redirection (IDER).” ¶[0112], “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to reimage the client device with a clean operating system image.”).
Regarding Claim 12, Thakur in view of Mitra teaches: The method of claim 9, wherein the first missing or corrupted agent comprises a first missing or corrupted security agent (Thakur, ¶[0017], “the enterprise security controller may be able to aggregate relevant and useful information to determine, for example, that a malware outbreak has occurred. For example, if a large number of hosts suddenly and near simultaneously lose their antivirus agents, then the enterprise security controller may determine that a malware outbreak is probably underway, and take appropriate remedial action.”).
Regarding Claim 13, Thakur discloses: A system comprising:
a server configured to detect a first missing or corrupted agent installed on a first machine, wherein the server is communicably coupled to the first machine (Thakur, ¶[0065], “[0065] In block 410, an interface may be provided to register appropriate processes for monitoring. For example, vPro™ “agent presence” feature may be used to register one or more applications for monitoring.”); and
a computer system configured to (Thakur, ¶[0013], “it is recognized in the present Specification that interference with a system management agent or other critical process may itself be a reliable indicator of the presence of malware … Thus, if the system can be monitored, and attempts to disable or otherwise obstruct critical processes are detected, automated remediation can be initiated from a server.”):
determine a first service, that is associated with the first missing or corrupted agent, is non-operational (Thakur, ¶[0020], “… Intel® vPro™ provides (“out of the box”) a feature called “agent presence,” which can be configured to monitor a particular process, and report to an enterprise security controller if that process goes down.” ¶[0068] “In block 430, when any monitored process fails or is forcefully closed by a user or malicious app (optionally as determined by ESC 140), a remedial action may be taken.”), and
restart the non-operational first service on the first machine, wherein automatic remediation comprises to restart the first service on the first machine (Thakur, ¶[0013], “if the system can be monitored, and attempts to disable or otherwise obstruct critical processes are detected, automated remediation can be initiated from a server.”¶[0073], “e. If a monitored process is still not stabilizing, then apply the remediation action, including for example a process restart or applying System defense policy on the client.” ¶[0084-0089], “[0084] … remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0089] e. … remediating the system using a pre-defined cleaner/rescue image” ¶[0110] “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to restart a monitored process.”),
wherein the computer system is communicably coupled to the server,
wherein the computer system is further configured to reimage the first machine, wherein the automatic remediation further comprises to reimage the first machine (Thakur, ¶[0084], “remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0087] c. Running diagnostic commands from the server to retrieve all events. [0088] d. Notifying security administrator 150 for issues with mission-critical services. [0089] e. If system is infected then remediating the system using a pre-defined cleaner/rescue image using integrated drive electronics (IDE)-redirection (IDER).” ¶[0112], “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to reimage the client device with a clean operating system image.”).
Thakur does not explicitly teach the following limitation that Mitra teaches:
for a detection count less than or equal to a threshold (Mitra, ¶[0075], “… then the timer 250 increases (340) a counter. If (350) the counter is less than a threshold … Otherwise, if (350) the counter is greater than a threshold, …”):
for the detection count greater than the threshold (Mitra, ¶[0075], “… then the timer 250 increases (340) a counter. If (350) the counter is less than a threshold … Otherwise, if (350) the counter is greater than a threshold, …”):
wherein the server is further configured to redetect the first missing or corrupted agent installed on the first machine (Note: Thakur teaches “detecting the first missing or corrupted agent installed on a first machine,” while Mitra is only relied upon to teach “redetecting.” Mitra, ¶[0075], “the detection engine 240 computes (320) a fingerprint for each incoming write 280 to the VM. … the detection engine 240 operates asynchronously with respect to the virtual machine.”), and
Thakur in view of Mitra is analogous art because the references are from the “same field of endeavor” and are from the same “problem solving area.” Namely, they pertain to the field of “remediation methods in cybersecurity.” It would have been obvious for one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Thakur with Mitra by implementing
“for a detection count less than or equal to a threshold:
for the detection count greater than the threshold:
redetecting the first missing or corrupted agent installed on the first machine”
Because remediation action can be taken based on a detection count compared to a threshold (Mitra, ¶[0065]).
Regarding Claim 18, Thakur in view of Mitra teaches: The system of claim 13, wherein the server is further configured to detect a second missing or corrupted agent installed on a second machine (Thakur, ¶[0065], “[0065] In block 410, an interface may be provided to register appropriate processes for monitoring. For example, vPro™ “agent presence” feature may be used to register one or more applications for monitoring.”),
wherein the server is further communicably coupled to the second machine, and wherein the computer system is further configured to:
determine a second service associated with the second missing or corrupted agent is operational (Thakur, ¶[0020], “… Intel® vPro™ provides (“out of the box”) a feature called “agent presence,” which can be configured to monitor a particular process, and report to an enterprise security controller if that process goes down.” ¶[0068] “In block 430, when any monitored process fails or is forcefully closed by a user or malicious app (optionally as determined by ESC 140), a remedial action may be taken.”), and
reinstall the second missing or corrupted agent on the second machine, wherein the automatic remediation further comprises to reinstall the second missing or corrupted agent on the second machine (Thakur, ¶[0013], “if the system can be monitored, and attempts to disable or otherwise obstruct critical processes are detected, automated remediation can be initiated from a server.” ¶[0073], “e. If a monitored process is still not stabilizing, then apply the remediation action, including for example a process restart or applying System defense policy on the client.” ¶[0084-0089], “[0084] … remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0089] e. … remediating the system using a pre-defined cleaner/rescue image.” ¶[0109], “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to reinstall a monitored application.”).
Regarding Claim 19, Thakur in view of Mitra teaches: The system of claim 18, wherein the server is further configured to redetect the second missing or corrupted agent installed on the second machine (Thakur, ¶[0076-0083], “[0076] In block 480, … self-learning engine 326 may enter an unsupervised self-learning mode. [0077] In one or more embodiments, criteria to trigger a remediation process may include, by way of non-limiting example: [0078] a. Usage of high system resources compare to pre-defined consumption or previous usage pattern. [0079] b. Change of process identifier for a continuous running process. [0080] c. Removal/uninstallation of an application without removing the process monitoring from server. [0081] d. Interrupts and errors from a monitored process. [0082] e. Any system resource leak from a monitored process. [0083] f. Monitoring process is down or not sending heartbeat to agent presence monitor.”),
wherein the computer system is further configured to reimage the second machine, and wherein the automatic remediation further comprises to reimage the second machine (Thakur, ¶[0084], “remediation actions may include the following, by way of non-limiting example: [0085] a. Reinstalling the application (if removed or corrupt). [0086] b. Re-starting the process. [0087] c. Running diagnostic commands from the server to retrieve all events. [0088] d. Notifying security administrator 150 for issues with mission-critical services. [0089] e. If system is infected then remediating the system using a pre-defined cleaner/rescue image using integrated drive electronics (IDE)-redirection (IDER).” ¶[0112], “There is further disclosed an example, wherein the remedial action comprises causing the out-of-band management agent to reimage the client device with a clean operating system image.”).
Regarding Claim 20, Thakur in view of Mitra teaches: The system of claim 13, wherein the first missing or corrupted agent comprises a first missing or corrupted security agent (Thakur, ¶[0017], “the enterprise security controller may be able to aggregate relevant and useful information to determine, for example, that a malware outbreak has occurred. For example, if a large number of hosts suddenly and near simultaneously lose their antivirus agents, then the enterprise security controller may determine that a malware outbreak is probably underway, and take appropriate remedial action.”).
Claims 2-3 and 14-15 are rejected under 35 U.S.C. 103 as being unpatentable over Thakur et al. (US Patent Application Publication No. US 2022/0309157 A1, hereinafter, Thakur) in view of Mitra et al. (US Patent Application Publication No. US 2023/0177157 A1, hereinafter, Mitra) and further in view of Langton et al. (US Patent Application Publication No. US 2016/0292419 A1, hereinafter, Langton).
Regarding Claim 2, Thakur in view of Mitra teaches: The method of claim 1, further comprising
Thakur in view of Mitra does not explicitly teach the following limitation that Langton teaches:
updating an agent repository comprising increasing the detection count associated with the first missing or corrupted agent by one (Langton, ¶[0095], “security device 220 may use a malware counter for a file.” ¶[0109], “… increments malware counters associated with FileA and FileB to a value of one, and increments malware counters associated with FileF and FileH to a value of two.”).
Thakur in view of Mitra and and further in view of Langton is analogous art because the references are from the “same field of endeavor” and are from the same “problem solving area.” Namely, they pertain to the field of “information security systems.” It would have been obvious for one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Thakur in view of Mitra with Langton to
“updating an agent repository comprising increasing a detection count associated with the first missing or corrupted agent by one”
Because the device may identify a plurality of files for a multi-file malware analysis (Langton, Abstract).
Regarding Claim 3, Thakur in view of Mitra and further in view of Langton teaches: The method of claim 2, wherein redetecting the first missing or corrupted agent comprises: updating the agent repository by increasing the detection count by one (Langton, ¶[0095], “security device 220 may use a malware counter for a file.” ¶[0109], “… increments malware counters associated with FileA and FileB to a value of one, and increments malware counters associated with FileF and FileH to a value of two.”).
Regarding Claim 14, Thakur in view of Mitra and further in view of Langton teaches: The system of claim 13, wherein the computer system is further configured to update an agent repository comprising increasing the detection count associated with the first missing or corrupted agent by one (Langton, ¶[0095], “security device 220 may use a malware counter for a file.” ¶[0109], “… increments malware counters associated with FileA and FileB to a value of one, and increments malware counters associated with FileF and FileH to a value of two.”).
Regarding Claim 15, Thakur in view of Mitra and further in view of Langton teaches: The system of claim 14, wherein to redetect the first missing or corrupted agent comprises: update the agent repository by increasing the detection count by one (Langton, ¶[0095], “security device 220 may use a malware counter for a file.” ¶[0109], “… increments malware counters associated with FileA and FileB to a value of one, and increments malware counters associated with FileF and FileH to a value of two.”).
Claims 4-5 and 16-17 are rejected under 35 U.S.C. 103 as being unpatentable over Thakur et al. (US Patent Application Publication No. US 2022/0309157 A1, hereinafter, Thakur) in view of Mitra et al. (US Patent Application Publication No. US 2023/0177157 A1, hereinafter, Mitra) and further in view of Langton et al. (US Patent Application Publication No. US 2016/0292419 A1, hereinafter, Langton) and Adams et al. (US Patent No. US 9,729,572 B1, hereinafter, Adams).
Regarding Claim 4, Thakur in view of Mitra and further in view of Langton teaches: The method of claim 2, wherein updating the agent repository further comprises
Thakur in view of Mitra and further in view of Langton does not explicitly teach the following limitation that Adams teaches:
notifying a user of the first machine that the first machine has the first missing or corrupted agent (Adams, col 10, line 8-16, “security device 220 may notify a user of client device 210, when causing the one or more remediation actions to be executed.”).
Thakur in view of Mitra and Further in view of Langton and Adams is analogous art because the references are from the “same field of endeavor” and are from the same “problem solving area.” Namely, they pertain to the field of “information security systems.” It would have been obvious for one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Thakur in view of Mitra and further in view of Langton with Adams to
“notifying a user of the first machine that the first machine has the first missing or corrupted agent”
Because the device may cause the one or more remediation actions to be executed (Adams, Abstract).
Regarding Claim 5, Thakur in view of Mitra and further in view of Langton and Adams teaches: The method of claim 2, wherein updating the agent repository further comprises notifying a proponent of the first machine that the first machine has the first missing or corrupted agent (Adams, col 10, line 8-16, “security device 220 may provide a notification to a user device associated with an IT agent, an administrator, or the like indicating that the one or more remediation actions have been selected and executed.”).
Regarding Claim 16, Thakur in view of Mitra and further in view of Langton and Adams teaches: The system of claim 14, wherein to update the agent repository further comprises notifying a user of the first machine that the first machine has the first missing or corrupted agent (Adams, col 10, line 8-16, “security device 220 may notify a user of client device 210, when causing the one or more remediation actions to be executed.”).
Regarding Claim 17, Thakur in view of Mitra and further in view of Langton and Adams teaches: The system of claim 14, wherein to update the agent repository further comprises notifying a proponent of the first machine that the first machine has the first missing or corrupted agent (Adams, col 10, line 8-16, “security device 220 may provide a notification to a user device associated with an IT agent, an administrator, or the like indicating that the one or more remediation actions have been selected and executed.”).
CONCLUSION
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to EDGAR W XIE whose telephone number is (703)756-4777. The examiner can normally be reached Monday - Friday, 8:00am - 5:00pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, JEFFREY PWU can be reached at (571)272-6798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/EDGAR W XIE/Examiner, Art Unit 2433
/WASIKA NIPA/Primary Examiner, Art Unit 2433