Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Detailed Action
Claims and Request for Continued Examination (RCE) filed on 06/09/2026 for patent application 18/469,314 have been acknowledged. Claims 1-13 and 15-20 are currently pending and have been considered below. Claims 1, 12, and 20 are independent claims. Claims 11, 12, and 20 have been amended. No new claims have been added.
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 06/09/2026 has been entered.
Response to Arguments
Applicant’s arguments with respect to claims 1-8, 11-13, 15-17, and 19-20 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Thus, the 35 USC 103 rejection of claims 1-8, 11-13, 15-17, and 19-20 is maintained.
Claim Objections
Claims 9-10 and 18 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-8, 11-13, 15-17, and 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Ben-Noon et al. (US Patent No. US 12,445,493 B2, hereinafter, Ben-Noon) in view of Thomas et al. (US Patent Application No. US 20230111304 A1).
Regarding Claim 1, Ben-Noon discloses: A system, comprising: a computer system comprising a processor programmed to:
receive, from a monitored system, user-specific behavior data that indicates one or more types of computer activities requested by a requester (Ben-Noon, col 3, line 1-12, “In addition, user interactions with the SWB may be monitored locally or by CyberSafe security hub. As a result, communications between the UE and MyCompany and actions of a MyCompany user interfacing with the UE are substantially completely visible to CyberSafe and to MyCompany and may be processed by the SWB, the hub and/or other trusted components associated with MyCompany.”);
identify a behavior profile that was generated during a training phase to learn behaviors of the requester, the behavior profile including information that identifies one or more computer activities that were monitored during the training phase (Ben-Noon, col 17, line 21-43, “in a block 306, browser SWB.sub.b uploads sets … to the CyberSafe security hub 52 (FIG. 1). … Expected values may be determined for a plurality of instances of session CCSESS.sub.n,s for user U.sub.n. … the expected values for a given user MyCompany user U.sub.n determine a user specific normal behavior pattern for a CCSESS.sub.n,s. … user specific normal behavior patterns and group normal behavior patterns determined by the CyberSafe hub and/or a browser SWB.sub.b are stored in a memory.”);
provide, during a detection phase, the user-specific behavior data to a behavior classifier to detect whether the user-specific behavior data is anomalous (Ben-Noon, col 17, line 60 – col 18, line 4, “In a block 316, the given SWB.sub.b monitors current session CCSESS.sub.n′,s′ to accumulate, process locally and upload data for CCaaS-KPI(n′,s′), UE-KPI(n′,s′,e′), U-KPI(n′,s′), SMETA(n′,s′) for the current session … and/or to detect occurrence of anomalous events.”),
generate, as an output of the behavior classifier, an anomaly classification based on the user-specific behavior data and the behavior profile, wherein the anomaly classification indicates a predicted anomalousness of the user-specific behavior data with respect to the behavior profile (Ben-Noon, col 18, line 5-30, “an anomalous event is an event that breaches normal behavior or an event that breaches MyCompany and/or CyberSafe policy. By way of example, a breach of a normal pattern may comprise a deviation of a given KPI monitored by the given SWB.sub.b from an expected value of the KPI by an amount greater than a standard deviation established for the KPI multiplied by a predetermined coefficient.”) and
is used to determine whether a mitigative action is to be taken in response to the one or more types of activities requested by the requester (Ben-Noon, col 18, line 31-57, “in a decision block 320 the given SWB.sub.b determines if, based on CyberSafe hub 52 (FIG. 1) and/or MyCompany policy, the anomalous event warrants a response.”); and
Thomas, ¶[0119], “events are continuously analyzed against a baseline. The baseline may be adjusted to account for normal behavior. Comparison to baselines may include looking for outliers and anomalies as well as impossible events. For example, if a user logs on from Germany and then logs in from San Francisco, that may be considered impossible.”)
Ben-Noon does not explicitly teach the following limitation that Thomas teaches:
wherein the behavior classifier is programmed to compare each of a plurality of behavior data points of the user-specific behavior data with corresponding expected values in the behavior profile and determine, based on the comparison, a plurality of deviation values; the plurality of deviation values determined from the comparison of the user-specific behavior data (Thomas, ¶[0157], “The detection engine 1122 may compare new events 1106 generated by an entity, as recorded in the event stream 1114, to the entity model 1120 that characterizes a baseline of expected activity. By representing the entity model 1120 and the event vectors 1110 in a common, or related, vector space, deviations from expected behavior can usefully be identified based on the vector distance between one or more event vectors 1110 and the entity model 1120.” ¶[0147], “It will also be appreciated that events 1106 and/or event vectors 1110 may usefully be labelled in a variety of ways. … the entity may include a user, a physical device, … an application”)
transmit, to the monitored system, the anomaly classification (Thomas, ¶[0143], “A detection engine 1122 may be applied to the event stream 1114 in order to detect unusual or malicious activity, e.g., based on the entity models 1120 or any other techniques.”)
Ben-Noon in view of Thomas is analogous art because they are from the “same field of endeavor” and are from the same “problem solving area.” Namely, they pertain to the field of “threat detection of users and devices.” It would have been obvious for one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Ben-Noon with Thomas to include:
“wherein the behavior classifier is programmed to compare each of a plurality of behavior data points of the user-specific behavior data with corresponding expected values in the behavior profile and determine, based on the comparison, a plurality of deviation values;
the plurality of deviation values determined from the comparison of the user-specific behavior data
transmit, to the monitored system, the anomaly classification”
because, the disclosure teaches a platform for threat investigation in an enterprise network receives threat data from managed endpoints (Thomas, Abstract).
Regarding Claim 2, Ben-Noon in view of Thomas teaches: The system of claim 1, wherein to receive the behavior data, the processor is further programmed to:
receive the behavior data from an embedded agent of the computer system, the embedded agent operating at a device of the monitored system to monitor the one or more types of computer activities without modifying a process that provides the one or more computer activities (Thomas, ¶[0145] “The local security agent 1108 may collect events 1106 from sensors 1104 on the compute instance 1102, and form the collected events 1106 into event vectors 1110 for communication to the threat management facility 1112. The sensors 1104 and/or local security agent 1108 may usefully process events 1106 in a number of ways in order to facilitate communication, computational efficiency, or downstream processing.”).
Regarding Claim 3, Ben-Noon in view of Thomas teaches: The system of claim 2, further comprising:
a device of the monitored system, wherein the device is programmed via developer coding logic that encodes one or more monitoring parameters that each identifies a permitted type of computer activity that the embedded agent is permitted to monitor; and
cause, based on the developer coding logic, the embedded agent to monitor only the permitted type of computer activity specified by the one or more monitoring parameters (Thomas, ¶[0145] “The local security agent 1108 may collect events 1106 from sensors 1104 on the compute instance 1102, and form the collected events 1106 into event vectors 1110 for communication to the threat management facility 1112. The sensors 1104 and/or local security agent 1108 may usefully process events 1106 in a number of ways in order to facilitate communication, computational efficiency, or downstream processing.”).
Regarding Claim 4, Ben-Noon in view of Thomas teaches: The system of claim 2, further comprising:
a device of the monitored system, wherein the device is programmed with the embedded agent to:
identify the mitigative action based on the anomaly classification and one or more mitigation rules; and
execute the mitigative action responsive to a request to perform the one or more computer activities (Thomas, ¶[0146], “the local security agent 1108 may locally analyze events 1106 and/or event vectors 1110 in order to permit suitable prioritization, as well as to support local detection and response to malicious, or potentially malicious activity.” ¶[0159], “this may include deployment of known remediations for malicious activity such as quarantine, termination of network communications, termination of processes or applications, an increase in local monitoring activity on affected compute instances 1102, messages to a network administrator, filtering of network activity, antivirus scans, deployment of security patches or fixes, and so forth.”).
Regarding Claim 5, Ben-Noon in view of Thomas discloses: The system of claim 1, wherein to generate the anomaly classification, the processor is further programmed to:
determine a vector value based on a monitored value of a computer activity and an expected value of the computer activity from the behavior profile (Thomas, ¶[0157], “By representing the entity model 1120 and the event vectors 1110 in a common, or related, vector space, deviations from expected behavior can usefully be identified based on the vector distance between one or more event vectors 1110 and the entity model 1120.”); and
transform the vector value to a sub-classification score, wherein the anomaly classification is based on the sub-classification score (Thomas,¶[0327], “The local threat indication may also or instead include a classification indicating a category of malicious activity associated with events detected on the endpoint.”).
Regarding Claim 6, Ben-Noon in view of Thomas teaches: The system of claim 5, wherein the behavior data comprises context data that specifies a context in which the computer activity was requested, and wherein the processor is further programmed to (Thomas, ¶[0166] “the filtered event stream may be arranged around anchor points such as a file, a domain name, or any other useful piece of data or metadata for which the presence can be monitored on an endpoint.”):
determine a contextual vector value based on a monitored contextual value of the data for the computer activity and an expected value of the context data from the behavior profile (Thomas, ¶[0157], “The detection engine 1122 may compare new events 1106 generated by an entity, as recorded in the event stream 1114, to the entity model 1120 that characterizes a baseline of expected activity. By representing the entity model 1120 and the event vectors 1110 in a common, or related, vector space, deviations from expected behavior can usefully be identified based on the vector distance between one or more event vectors 1110 and the entity model 1120.”); and
transform the contextual vector value to a contextual sub-classification score, wherein the anomaly classification is further based on the contextual sub-classification score (Thomas, ¶[0328], “the method 2400 may include receiving a contextual threat score calculated by a threat management facility based on event data received from contextual information received at the threat management facility. The threat management facility may use any context, event information, or the like, as generally described herein, and may evaluate a threat based on data from the endpoint”).
Regarding Claim 7, Ben-Noon in view of Thomas teaches: The system of claim of claim 6, wherein the context data comprises a time and/or date of the computer activity (Ben-Noon, col 16, line 55 – col 17, line 20, “comprise data components that provide values for at least one, or any combination of more than one of: ... Session ToD (Time of Day); session duration.” Col 34, line 14-21, “Talon may provide information such as how long a tab was open, length of user 907 activity in a service, what actions has the user 907 taken within the service.”).
Regarding Claim 8, Ben-Noon in view of Thomas teaches: The system of claim of claim 6, wherein the context data comprises a rate of the computer activity over time (Ben-Noon, col 16, line 55 – col 17, line 20, “comprise data components that provide values for at least one, or any combination of more than one of: ... Session ToD (Time of Day); session duration.” Col 34, line 14-21, “Talon may provide information such as how long a tab was open, length of user 907 activity in a service, what actions has the user 907 taken within the service.”).
Regarding Claim 11, Ben-Noon in view of Thomas teaches: The system of claim 1, wherein the processor is further programmed to: re-learn the behavior profile based on the behavior data and/or new behavior data (Thomas, ¶[0152], “It will also be understood that, once an entity model is created, the entity model may usefully be updated, which may occur at any suitable intervals according to, e.g., the length of time to obtain a stable baseline, the amount of activity by the entity, the importance of the entity (e.g., to security, operation of a compute instance 1102, and so forth), or any other factors.”).
Regarding Claim 12, Ben-Noon discloses: A method, comprising:
receiving, by a processor of a computer system, from a monitored system, user-specific behavior data that indicates one or more types of computer activities requested by a requester (Ben-Noon, col 3, line 1-12, “In addition, user interactions with the SWB may be monitored locally or by CyberSafe security hub. As a result, communications between the UE and MyCompany and actions of a MyCompany user interfacing with the UE are substantially completely visible to CyberSafe and to MyCompany and may be processed by the SWB, the hub and/or other trusted components associated with MyCompany.”);
identifying, by the processor, a behavior profile that was generated during a training phase to learn behaviors of the requester, the behavior profile including information that identifies one or more computer activities that were monitored during the training phase (Ben-Noon, col 17, line 21-43, “in a block 306, browser SWB.sub.b uploads sets … to the CyberSafe security hub 52 (FIG. 1). … Expected values may be determined for a plurality of instances of session CCSESS.sub.n,s for user U.sub.n. … the expected values for a given user MyCompany user U.sub.n determine a user specific normal behavior pattern for a CCSESS.sub.n,s. … user specific normal behavior patterns and group normal behavior patterns determined by the CyberSafe hub and/or a browser SWB.sub.b are stored in a memory.”);
providing, by the processor, during a detection phase, the user-specific behavior data to a behavior classifier to detect whether the user-specific behavior data is anomalous (Ben-Noon, col 17, line 60 – col 18, line 4, “In a block 316, the given SWB.sub.b monitors current session CCSESS.sub.n′,s′ to accumulate, process locally and upload data for CCaaS-KPI(n′,s′), UE-KPI(n′,s′,e′), U-KPI(n′,s′), SMETA(n′,s′) for the current session … and/or to detect occurrence of anomalous events.”);
generating, by the processor, as an output of the behavior classifier, an anomaly classification based on the user-specific behavior data and the behavior profile, wherein the anomaly classification indicates a predicted anomalousness of the user-specific behavior data with respect to the behavior profile (Ben-Noon, col 18, line 5-30, “an anomalous event is an event that breaches normal behavior or an event that breaches MyCompany and/or CyberSafe policy. By way of example, a breach of a normal pattern may comprise a deviation of a given KPI monitored by the given SWB.sub.b from an expected value of the KPI by an amount greater than a standard deviation established for the KPI multiplied by a predetermined coefficient.”) and
is used to determine whether a mitigative action is to be taken in response to the one or more types of activities requested by the requester (Ben-Noon, col 18, line 31-57, “in a decision block 320 the given SWB.sub.b determines if, based on CyberSafe hub 52 (FIG. 1) and/or MyCompany policy, the anomalous event warrants a response.”); and
Ben-Noon does not explicitly teach the following limitation that Thomas teaches:
wherein the behavior classifier is programmed to compare each of a plurality of behavior data points of the user-specific behavior data with corresponding expected values in the behavior profile and determine, based on the comparison, a plurality of deviation values; the plurality of deviation values determined from the comparison of the user-specific behavior data (Thomas, ¶[0157], “The detection engine 1122 may compare new events 1106 generated by an entity, as recorded in the event stream 1114, to the entity model 1120 that characterizes a baseline of expected activity. By representing the entity model 1120 and the event vectors 1110 in a common, or related, vector space, deviations from expected behavior can usefully be identified based on the vector distance between one or more event vectors 1110 and the entity model 1120.” ¶[0147], “It will also be appreciated that events 1106 and/or event vectors 1110 may usefully be labelled in a variety of ways. … the entity may include a user, a physical device, … an application”)
transmit, to the monitored system, the anomaly classification (Thomas, ¶[0143], “A detection engine 1122 may be applied to the event stream 1114 in order to detect unusual or malicious activity, e.g., based on the entity models 1120 or any other techniques.”)
Ben-Noon in view of Thomas is analogous art because they are from the “same field of endeavor” and are from the same “problem solving area.” Namely, they pertain to the field of “threat detection of users and devices.” It would have been obvious for one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Ben-Noon with Thomas to include:
“wherein the behavior classifier is programmed to compare each of a plurality of behavior data points of the user-specific behavior data with corresponding expected values in the behavior profile and determine, based on the comparison, a plurality of deviation values;
the plurality of deviation values determined from the comparison of the user-specific behavior data
transmit, to the monitored system, the anomaly classification”
because, the disclosure teaches a platform for threat investigation in an enterprise network receives threat data from managed endpoints (Thomas, Abstract).
Regarding Claim 13, Ben-Noon in view of Thomas teaches: The method of claim 12, wherein receiving the behavior data comprises: receiving the behavior data from an embedded agent of the computer system, the embedded agent operating at a device of the monitored system to monitor the one or more types of computer activities without modifying a process that provides the one or more computer activities (Thomas, ¶[0145] “The local security agent 1108 may collect events 1106 from sensors 1104 on the compute instance 1102, and form the collected events 1106 into event vectors 1110 for communication to the threat management facility 1112. The sensors 1104 and/or local security agent 1108 may usefully process events 1106 in a number of ways in order to facilitate communication, computational efficiency, or downstream processing.”).
Regarding Claim 15, Ben-Noon in view of Thomas teaches: The method of claim 12, further comprising:
identifying, by a device of the monitored system, the mitigative action based on the anomaly classification and one or more mitigation rules; and
executing, by the device, the mitigative action responsive to a request to perform the one or more computer activities (Thomas, ¶[0146], “the local security agent 1108 may locally analyze events 1106 and/or event vectors 1110 in order to permit suitable prioritization, as well as to support local detection and response to malicious, or potentially malicious activity.” ¶[0159], “this may include deployment of known remediations for malicious activity such as quarantine, termination of network communications, termination of processes or applications, an increase in local monitoring activity on affected compute instances 1102, messages to a network administrator, filtering of network activity, antivirus scans, deployment of security patches or fixes, and so forth.”).
Regarding Claim 16, Ben-Noon in view of Thomas teaches: The method of claim 12, wherein generating the anomaly classification comprises:
determining a vector value based on a monitored value of a computer activity and an expected value of the computer activity from the behavior profile (Thomas, ¶[0157], “By representing the entity model 1120 and the event vectors 1110 in a common, or related, vector space, deviations from expected behavior can usefully be identified based on the vector distance between one or more event vectors 1110 and the entity model 1120.”); and
transforming the vector value to a sub-classification score, wherein the anomaly classification is based on the sub-classification score (Thomas,¶[0327], “The local threat indication may also or instead include a classification indicating a category of malicious activity associated with events detected on the endpoint.”).
Regarding Claim 17, Ben-Noon in view of Thomas teaches: The method of claim 16, wherein the behavior data comprises context data that specifies a context in which the computer activity was requested, the method further comprising (Thomas, ¶[0166] “the filtered event stream may be arranged around anchor points such as a file, a domain name, or any other useful piece of data or metadata for which the presence can be monitored on an endpoint.”):
determining a contextual vector value based on a monitored contextual value of the data for the computer activity and an expected value of the context data from the behavior profile (Thomas, ¶[0157], “The detection engine 1122 may compare new events 1106 generated by an entity, as recorded in the event stream 1114, to the entity model 1120 that characterizes a baseline of expected activity. By representing the entity model 1120 and the event vectors 1110 in a common, or related, vector space, deviations from expected behavior can usefully be identified based on the vector distance between one or more event vectors 1110 and the entity model 1120.”); and
transform the contextual vector value to a contextual sub-classification score, wherein the anomaly classification is further based on the contextual sub-classification score (Thomas, ¶[0328], “the method 2400 may include receiving a contextual threat score calculated by a threat management facility based on event data received from contextual information received at the threat management facility. The threat management facility may use any context, event information, or the like, as generally described herein, and may evaluate a threat based on data from the endpoint”).
Regarding Claim 19, Ben-Noon in view of Thomas teaches: The method of claim 12, the method further comprising: re-learning the behavior profile based on the behavior data and/or new behavior data (Thomas, ¶[0152], “It will also be understood that, once an entity model is created, the entity model may usefully be updated, which may occur at any suitable intervals according to, e.g., the length of time to obtain a stable baseline, the amount of activity by the entity, the importance of the entity (e.g., to security, operation of a compute instance 1102, and so forth), or any other factors.”).
Regarding Claim 20, Ben-Noon discloses: A computer readable medium storing instructions of an embedded agent that, when executed by one or more processors, program the one or more processors to:
access a request by a requester to execute a computer activity (Ben-Noon, col 3, line 1-12, “In addition, user interactions with the SWB may be monitored locally or by CyberSafe security hub. As a result, communications between the UE and MyCompany and actions of a MyCompany user interfacing with the UE are substantially completely visible to CyberSafe and to MyCompany and may be processed by the SWB, the hub and/or other trusted components associated with MyCompany.”);
obtain context data associated with the computer activity (Ben-Noon, col 16, line 55 – col 17, line 20, “A CCaaS-KPI(n,s) may by way of example comprise KPIs that provide values for at least one, or any combination of more than one of: CPU usage; memory usage; bandwidth usage; response time to a user's request; throughput; latency; request error rate; resources accessed; permission changes; and/or network requests.”);
generate user-specific behavior data comprising an identification of the computer activity and the context data (Ben-Noon, col 17, line 60 – col 18, line 4, “in a block 314 a particular user U.sub.n′ using a given browser SWB.sub.b in a given UE.sub.e requests and is permitted access to and use of a particular My-CCaaS.sub.s′ and engages in a “current” session CCSESS.sub.n′,s′ with My-CCaaS.sub.s′. In a block 316, the given SWB.sub.b monitors current session CCSESS.sub.n′,s′ to accumulate, process locally and upload data for CCaaS-KPI(n′,s′), UE-KPI(n′,s′,e′), U-KPI(n′,s′), SMETA(n′,s′) for the current session to add to data already accumulated.”);
transmit the user-specific behavior data to a computer system for anomaly classification of the user-specific behavior data (Ben-Noon, col 17, line 44 – col 18, line 4, “in a block 310, SWB.sub.b and/or the CyberSafe hub processes data provided by CCaaS-KPI(n,s), UE-KPI(n,s), U-KPI(n,s), and/or SMETA(n,s) to determine cyber vulnerabilities associated with MyCompany users using a My-CCaaS.sub.s and/or with a specific MyCompany user.”);
the anomaly classification representing a prediction of an extent to which the computer activity deviates from a learned normal behavior based on previously learned computer activities of the requester (Ben-Noon, col 18, line 5-30, “an anomalous event is an event that breaches normal behavior or an event that breaches MyCompany and/or CyberSafe policy. By way of example, a breach of a normal pattern may comprise a deviation of a given KPI monitored by the given SWB.sub.b from an expected value of the KPI by an amount greater than a standard deviation established for the KPI multiplied by a predetermined coefficient.”);
access one or more mitigation rules corresponding to the anomaly classification; and identify a mitigative action to take or no mitigative action to take based on the one or more mitigation rules (Ben-Noon, col 18, line 31-57, “in a decision block 320 the given SWB.sub.b determines if, based on CyberSafe hub 52 (FIG. 1) and/or MyCompany policy, the anomalous event warrants a response.”).
Ben-Noon does not explicitly teach the following limitation that Thomas teaches:
wherein the computer system is programmed to compare each of a plurality of behavior data points of the user-specific behavior data with corresponding expected values in the behavior profile and determine, based on the comparison, a plurality of deviation values; being based on the plurality of deviation values (Thomas, ¶[0157], “The detection engine 1122 may compare new events 1106 generated by an entity, as recorded in the event stream 1114, to the entity model 1120 that characterizes a baseline of expected activity. By representing the entity model 1120 and the event vectors 1110 in a common, or related, vector space, deviations from expected behavior can usefully be identified based on the vector distance between one or more event vectors 1110 and the entity model 1120.” ¶[0147], “It will also be appreciated that events 1106 and/or event vectors 1110 may usefully be labelled in a variety of ways. … the entity may include a user, a physical device, … an application”)
receive an anomaly classification from the computer system (Thomas, ¶[0143], “A detection engine 1122 may be applied to the event stream 1114 in order to detect unusual or malicious activity, e.g., based on the entity models 1120 or any other techniques.”)
Ben-Noon in view of Thomas is analogous art because they are from the “same field of endeavor” and are from the same “problem solving area.” Namely, they pertain to the field of “threat detection of users and devices.” It would have been obvious for one of ordinary skill in the art, before the effective filing date of the claimed invention, to modify Ben-Noon with Thomas to include:
“wherein the computer system is programmed to compare each of a plurality of behavior data points of the user-specific behavior data with corresponding expected values in the behavior profile and determine, based on the comparison, a plurality of deviation values;
being based on the plurality of deviation values
receive an anomaly classification from the computer system”
because, the disclosure teaches a platform for threat investigation in an enterprise network receives threat data from managed endpoints (Thomas, Abstract).
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to EDGAR W XIE whose telephone number is (703)756-4777. The examiner can normally be reached Monday - Friday, 8:00am - 5:00pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, JEFFREY PWU can be reached at (571)272-6798. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/EDGAR W XIE/ Examiner, Art Unit 2433
/WASIKA NIPA/ Primary Examiner, Art Unit 2433