DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claims 1-20 are pending. No claims are new or canceled. Claims 1, 7, 8, 14, 15, and 20 are amended. Claims 1, 8 and 15 are independent. Amendments to the claims have been accepted.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 02/04/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Response to Arguments
Applicant’s arguments, see pp.9-12 (pp. 1-4 of Remarks), filed 02/04/2026, with respect to the rejection of claims 1-3, 5, 7-20, 23, 14-17, and 19-20 under 35 U.S.C. § 103 have been fully considered and are persuasive. Therefore, the rejection of claims 1-3, 5, 7-20, 23, 14-17, and 19-20 under 35 U.S.C. § 103 of 11/04/2025 has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of Doron in view of Levin and Durairaj (see rejection below).
Claim Rejections - 35 USC § 103
The text of those sections of Title 35, U.S. Code not included in this action can be found in a prior Office action.
Claim(s) 1-2, 5, 7-9, 12, 14-16, and 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Doron (DORON et al., US 20190182274 A1, cited in a prior office action) in view of Levin (LEVIN et al., US 20200336506 A1) and Durairaj (Joseph Durairaj et al., US 11736527 B1)
Regarding claim 1, and substantially claims 8 and 15, Doron teaches a method comprising: detecting a plurality of first malicious activities associated with a first attack (¶48-¶50, ¶67, historic sequences of attacks (plurality of first malicious of activities associated with a first attack) are learned (detected) prior to the execution of the method); detecting a plurality of second malicious activities associated with a second attack (Fig. 3, Step 310, ¶38 ¶68, events data regarding the detection of attacks or breaches of security policies are gathered); predicting, based on the plurality of first malicious activities associated with the first attack, a future malicious activity associated with the second attack (¶69-¶71, a sequence is extracted from the events data and is used to predict subsequent attacks based on the historic attack sequence); and generating an alert for the predicted future malicious activity associated with the second attack (¶35, the attack predictor suggests mitigation actions that should be performed (alert)).
Doron does not teach but, in an analogous art, Levin teaches that the alert comprises one or more attributes (¶36, "Consequently, information associated with the predicted next alert 128, as well as the pattern of triggered alerts, can be displayed in a graphical user interface 132 so it can be reviewed by a security analyst before further malicious activity actually occurs. The information displayed to the security analyst 104 can include… The information can include a severity level associated with the predicted next alert. And the information can include mitigation steps that can help the security analyst 104 resolve a security incident.") derived from a previous alert generated for one of the plurality of first malicious activities associated with the first attack (¶25, patterns are developed to predict future alerts based on a pattern of triggered alerts. ¶34, "The next alert prediction module 118 can then apply the model 124 to triggered alerts that are received in association with a resource or a group of resources in order to identify a pattern of triggered alerts and predict a next alert 128 that is likely to be triggered in the pattern."). It would be obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to modify Doron using Levin to use a previous alert to develop the new alert because it allows for mitigating the next issue of the previous alert before it can occur in the current alert (Levin, ¶10).
Doron in view of Levin does not teach but, in an analogous art, Durairaj teaches that
the first attack relates to computing resources of a first entity; the second attack relates to computing resources of a second entity that is distinct from the first entity (16:17-25, 12:57-61, a timeline is constructed for enterprises (first/second distinct entities) in regard to events on a timeline, such as actions of an adversary); and the computing resources of the first entity are inaccessible to the second entity (9:63-10:3, the individual enterprises of a cohort cannot access each others' individual data (computing resources))
It would be obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to modify Doron in view of Levin using Durairaj to have the cybersecurity entities be different enterprises mutually inaccessible data because similar enterprises would likely have similar security concerns (Durairaj, 14:49-60) such that attacks on one could likely be performed on another of the same group, such that additional data can be gathered to protect the enterprises while maintaining the privacy of each individual enterprise (Durairaj, 9:63-10:3).
Regarding claim 2, and substantially claims 9 and 16, Doron in view of Levin and Durairaj teaches the method of claim 1, wherein: the plurality of first malicious activities comprises a first malicious activity and a second malicious activity (Doron, ¶57, a historic sequence of attack has a matching portion (first malicious activity) and a subsequent portion (second malicious activity)); the plurality of second malicious activities comprises a third malicious activity (Doron, ¶57, the current sequence of attack has a matching portion (third malicious activity)); and predicting the future malicious activity comprises calculating a similarity score between the first malicious activity and the third malicious activity (Doron, ¶55-¶57, when the distance between the sequences (similarity score between first and third malicious activities) are below a threshold, a match is determined, and subsequent attacks of the historic sequence are predicted as potential continuations of the current sequence).
Regarding claim 5, and substantially claims 12 and 19, Doron in view of Levin and Durairaj teaches the method of claim 2, wherein the plurality of first malicious activities corresponds to a first sequence of malicious activities, the first malicious activity preceding the second malicious activity in the first sequence; and wherein the plurality of second malicious activities corresponds to a second sequence of malicious activities, the third malicious activity being the last malicious activity in the second sequence (Doron, ¶59, ¶63, ¶71, attacks that continue the current sequence (third malicious activity of the second sequence) are predicted, such that the last malicious activity of the current sequence is the third sequence, by using the subsequent continuation attacks (second malicious activity after first malicious activity) of the historic sequence (first malicious activity)).
Regarding claim 7, and substantially claims 14 and 20, Doron in view of Levin and Durairaj teaches the method of claim 1. Levin further teaches that the one or more attributes of the previous alert generated for one of the plurality of first malicious activities associated with the first attack relating to the computing resources of the first entity comprises at least one of: a severity value; a priority value; a risk value; a confidence value; or a malicious activity metadata (Levin, "The features can include words that describe a type of alert, a severity level associated with the alert, a time at which the alert is triggered, and/or domain information associated with the alert.") (see claim 1 for motivation to combine).
Claims 3, 10, and 17 is/are rejected under 35 U.S.C. 103 as being unpatentable over Doron in view of Levin and Durairaj as applied to claims 2, 9, and 16 above, and further in view of Ben Ezra (BEN EZRA et al., US 20180069876 A1, cited in a prior office action).
Regarding claim 3, and substantially claims 10 and 17, Doron in view of Levin and Durairaj teaches the method of claim 2. Doron in view of Levin and Durairaj does not teach but, in an analogous art, Ben Ezra further teaches that calculating the similarity score comprises: comparing a first metadata of the first malicious activity to a corresponding second metadata of the third malicious activity to obtain a first difference value; comparing a third metadata of the first malicious activity to a corresponding fourth metadata of the third malicious activity to obtain a second difference value; and combining the first difference value and the second difference value to obtain the similarity score (Ben Ezra, ¶47, ¶53, events (malicious activities) are calculated as similar based on the number of identical features (compared corresponding pieces of metadata, combined to create the whole number). ¶32, the features that can be metadata are things like the source IP address of the attacker's computer or the destination address of a protected object).
It would be obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to further modify Doron in view of Levin and Durairaj using Ben Ezra to compare corresponding pieces of metadata of the malicious activities and combine them to obtain the similarity score because it allows for the modification of mitigation policies depending on the metadata, such as blocking a specific malicious IP address (Ben Ezra, ¶62).
Claims 4, 11, and 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Doron in view of Levin and Durairaj as applied to claims 2, 9, and 16 above, and further in view of Kharraz (Kharraz et al., US 10911477 B1, cited in a prior office action).
Regarding claim 4, and substantially claims 11 and 18, Doron in view of Levin and Durairaj teaches the method of claim 2. Although Doron hints at taking the calculating the distance between a malicious activity and a cluster (Doron, ¶59, the similarity is calculated between a sequence signature of the current sequences and of the cluster centroid of historic sequences), Doron in view of Levin and Durairaj does not teach the rest of the claimed invention. In an analogous art, Kharraz teaches that calculating the similarity score comprises: applying a clustering algorithm to the first malicious activity to obtain a first cluster; applying the clustering algorithm to the third malicious activity to obtain a second cluster; and calculating a distance between the first cluster and the second cluster, the distance representing the similarity score (7:39-58, malware domains are clustered into multiple clusters by applying hierarchical clustering algorithms, which further calculates the distance between clusters based on the similarity).
It would be obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to further modify Doron in view of Levin and Durairaj using Kharraz to cluster the malicious activities and calculate the distance between them because using a clustering algorithm decreases computational costs for determining similarity between a malicious activity and another malicious activity by grouping together similar activities (Kharraz, 7:9-26).
Claims 6 and 13 is/are rejected under 35 U.S.C. 103 as being unpatentable over Doron in view of Ben Ezra as applied to claims 5, 12, and 19 above, and further in view of Jurewicz (Jurewicz et al., "Set-to-sequence methods in machine learning: A review.", 2021, cited in a prior office action).
Regarding claim 6, and substantially claim 13, Doron in view of Levin and Durairaj teaches the method of claim 5, wherein a sequence of malicious activities is generated using a machine learning model trained to generate sequences of malicious activities given an input plurality of malicious activities (¶48-¶50, the sequence signatures (sequences of malicious activities) are generated using a trained LSTM Neural Network (machine learning model that is trained)). Doron in view of Levin and Durairaj does not teach but, in an analogous art, Jurewicz teaches that the first sequence is generated using a machine learning model trained to generate sequences given an input plurality (p.1, '1.1 What is Set-to-Sequence?', "Set-to-sequence encompasses a group of problems where input takes the form of unordered collections of elements and the output is an ordered sequence. These challenges can be approached as a machine learning problem, where models learn arbitrary functions for performing the set-to-sequence mapping.").
It would be obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to further modify Doron in view of Levin and Durairaj using Jurewicz to generate the first sequence of malicious activities using a machine learning model because machine learning allows for optimizing sequencing when an exhaustive search is not possible (Jurewicz, p.1, '1.1 What is Set-to-Sequence?', "Set-to-sequence covers combinatorial optimization and structure prediction problems where exhaustive search is often not tractable. Machine learning (ML) approaches to set-to-sequence combine set-encoding techniques with permutation learning and have found an exceptionally wide range of practical applications."), such as when a large set of malicious activities isn't already sequenced and isn't timestamped to create a sequence out of.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Oprea (Oprea et al., US 9838407 B1) teaches extracting data from HTTP logs to predict new malicious activities and close the gap between the time of compromise and the time of discovery (22:55-23:11)
Garyani (GARYANI et al., US 20230107335 A1) teaches methods of maintaining privacy and confidentiality between cloud tenants of a cloud service (¶111) while still being able to analyze data of a cyber-attack (¶64-¶65).
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to AMIR MAHDI HAJIABBASI whose telephone number is (703)756-5511. The examiner can normally be reached M-F 7:30-5 EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Catherine Thiaw can be reached at (571) 270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/A.M.H./
Amir Mahdi HajiabbasiExaminer, Art Unit 2407
/David Garcia Cervetti/Primary Examiner, Art Unit 2409