DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claims 1 and 13 are amended and independent. No claims are new or canceled. Claims 1-23 are pending. Amendment to the claims have been accepted.
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 03/30/2026 has been entered.
Response to Arguments
Applicant’s arguments, see pp. 6-8 (pp. 1-3 of Remarks), filed 03/30/2026, with respect to the rejection(s) of claim(s) 1 and 13 under 35 U.S.C. § 103 over Jeyakumar in view of Voros have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of 35 U.S.C. § 103 over Jeyakumar in view of Kearney. The remaining claims depending on claim 1 and 13 are under a new ground of rejection as well.
Claim Interpretation
The following is a quotation of 35 U.S.C. 112(f):
(f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph:
An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation(s) is/are: the term ‘unit’ in an Internet Protocol (IP)/domain extraction unit, a contextual data analysis unit, a multimodal unit, an image extraction unit, an image processing unit, and an aggregator/classifier unit in claims 1-8, 11-12.
Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof.
From the published specification:
¶25, " Each of these components in the system 100A or 100B is/runs on one or more computing units/appliances/devices/hosts (not shown) each having one or more processors and software instructions stored in a storage unit such as a non-volatile memory of the computing unit for practicing one or more processes.",
¶34, "It is appreciated that the number of processing units (sub-models) is for illustration purposes only and should not be construed as limiting the scope of the embodiments, as illustrated by FIGS. 1A and 1B. Moreover, it is appreciated that while the units are shown within the processor 140, they may be implemented in more than one processing unit and in a distributed fashion."
If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph.
Claim Rejections - 35 USC § 103
The text of those sections of Title 35, U.S. Code not included in this action can be found in a prior Office action.
Claim(s) 1, 3-4, 6-10, 12-13, 15, 17-21, and 23 is/are rejected under 35 U.S.C. 103 as being unpatentable over Jeyakumar (Jeyakumar et al., US 20200204572 A1, cited in a prior office action) in view of Kearney (Kearney et al., US 10891539 B1).
Regarding claim 1, and substantially claim 13, Jeyakumar teaches a system, comprising (¶176-¶179, the system is implemented by non-transitory medium storing instructions that are run by one or more processors to perform the functions of the invention):
an Internet Protocol (IP)/domain extraction unit configured to extract IP/domain data associated with a received electronic message (¶79, ¶133, ¶164, the threat detection platform (through the primary attribute extractor) extracts metadata from the received email, such as the IP addresses and domain information);
a transmitter/receiver configured to transmit the extracted IP/domain to a database storing statistical data associated with a plurality of IPs/domains, and wherein the transmitter/receiver is configured to receive a first type of data comprising statistical data associated with the extracted IP/domain from the database (¶29, "extract primary attributes from the past emails, generate corpus statistics based on the primary attributes, derive secondary attributes based on the primary attributes and the corpus statistics". Fig. 6, secondary extractors send information to the threat detection database and receive information from the threat detection database and primary extractors. ¶80, "The secondary attributes can be determined from a time series of primary attribute values (e.g., wherein each primary attribute value can be associated with a timestamp, such as the sent timestamp or receipt timestamp of the email)… domain information (e.g., domain age, whether the domain is blacklisted or whitelisted, whether the domain is internal or external, etc.)… One example of a primary attribute is a sender email address, while one example of a secondary attribute is the statistics of communications patterns from sender address to recipient", additional statistics related to the extracted data such as the statistics of communication patterns (such as the times when the emails are sent/received or the domain's age) of received emails from the domain (first type of data comprising statistical data associated with the extracted IP/domain, timestamps and associated domains) are extracted (the secondary attribute extractor) from the primary extractor and the threat detection database);
a contextual data analysis unit configured to generate a second type of data comprising context analysis data associated with a content of the received electronic message (¶80, "… whether the body of the communication includes one of a set of high-risk words, phrases, sentiments, or other content (e.g., whether the communication includes financial vocabulary, credential theft vocabulary, engagement vocabulary, non-ASCII content, attachments, links, etc.", the plurality of secondary extractors can also perform context analysis on the content of the email and determine whether it includes high-risk text (the determination being a category as a second type of data) in it); and
a multimodal unit configured to implement at least two sub-models, wherein the multimodal unit is further configured to generate an output based on analysis of the statistical data and the context analysis data by the at least two sub-models, and wherein the output is a cybersecurity threat associated with the received electronic message (Fig. 6, two analysis modules (at least two sub models) are explicitly shown feeding their inputs into the master detector, at least three models implied with ‘attack1 output’, ‘attack output’ and ‘attackN output’, ¶87, the analysis module detects attacks based on the secondary attributes (statistics, context). ¶18, "As further discussed below, the technologies described herein can leverage machine learning, heuristics, rules, human-in-the-loop feedback and labeling, or some other technique for detecting an attack (e.g., in real time or near real time) based on features extracted from a communication (e.g., an email) and/or context of the communication (e.g., recipient, sender, content, etc.).". ¶94, the output of the analysis modules is fed into a master detector).
Although Jeyakumar teaches at least two sub-models that utilize the statistical data and context analysis data to categorize the received electronic message, Jeyakumar does not explicitly teach that the two sub-models include a tabular sub-model associated with the first type of data and a contextual sub-model associated with the second type of data, wherein the tabular sub-model is configured to utilize the statistical data to categorize the received electronic message and the contextual sub-model is configured to utilize the context analysis data to categorize the received electronic message. However, in an analogous art, Kearney teaches a multimodal unit configured to implement at least two sub-models (15:49-54) including a tabular sub-model associated with the first type of data (15:36-42, 60-65, "The importance of a social media instance can depend on the time of creation of the instance. The time of day, week, month, or year can have an effect on the semantics associated with a particular social instance. In at least one embodiment, the system and method use a machine learning strategy that learns to associate instance classification with instance time of creation… The structured data classification model 1130 may process structured information 1170 through fully connected layers 1172 to fully connected layers 1174. The structured information 1170 may include geographical, temporal, demographic, user background information, and/or custom user input information.", structured temporal information associated with the timestamps for specific electronic messages and their point of origin (first type of data comprising statistical data associated with the extracted IP/domain) is analyzed through a structured data classification model (tabular model)) and a contextual sub-model associated with the second type of data (15:54-57, "The convolutional language classification model 1110 may process input text 1140 through word embeddings 1142 to LSTM layers 1144, and through convolutional layers 1152 to LSTM layers 1154."), wherein the tabular sub-model is configured to utilize the statistical data to categorize the received electronic message and the contextual sub-model is configured to utilize the context analysis data to categorize the received electronic message, wherein the multimodal unit is further configured to generate an output based on analysis of the statistical data and the context analysis data by the at least two sub-models (16:1-7, "The fully connected layers 1180 may thus incorporate text, image, and/or structured information to provide a prediction 1190 of greater accuracy than could be obtained by operation of the convolutional language classification model 1110, the image classification model 1120, or the structured data classification model 1130, alone.").
Jeyakumar and Kearney are analogous arts as they both deal with analyzing electronic messages to categorize them as good or bad (Jeyakumar, ¶18, messages are attacks or not. Kearney, 1:19-21, posted content in social media should be restricted or not restricted). One of ordinary skill in the art prior to the effective filing date of the invention could modify Jeyakumar using Kearney to implement the models of Kearney as the analysis modules of Jeyakumar to perform a multi-modal analysis of the secondary attributes (statistical information associated with the extracted IP/domain, contextual analysis data) to categorize the electronic messages with predictable results. It would be obvious to one of ordinary skill in the art prior to the effective filing date of the claimed invention to modify Jeyakumar using Kearney to perform a multi-modal analysis of the secondary attributes to categorize the electronic messages because it provides a greater prediction than input of any one type alone (Kearney, 16:1-7).
Regarding claim 3, Jeyakumar in view of Kearney teaches the system of Claim 1, wherein the generated context analysis data is a category associated with the received electronic message (Jeyakumar, ¶80, "… whether the body of the communication includes one of a set of high-risk words, phrases, sentiments, or other content (e.g., whether the communication includes financial vocabulary, credential theft vocabulary, engagement vocabulary, non-ASCII content, attachments, links, etc.", the plurality of secondary extractors perform context analysis on the content of the email and determine whether it includes high-risk text (the determination being a category as a second type of data)).
Regarding claim 4, and substantially claim 15, Jeyakumar in view of Kearney teaches the system of Claim 1. Kearney further teaches an image extraction unit and an image processing unit, wherein the image extraction unit is configured to extract an image within the received electronic message (Kearney, Fig. 16, 18-18-23, "Social media user profile information 1640 for the communication 112, image recognition and natural language processing classifications 1650 for the communication 112, an image 1660 from the communication, and an origination 1670 of the communication 112 may also be displayed.", images from the electronic communication are displayed after processing, such that the image is first extracted from the communication) and wherein the image processing unit is configured to identify the extracted image (Kearney, 15:57-59, "The image classification model 1120 may process images 1160 through convolutional layers 1162 to fully connected layers 1164."), and wherein the multimodal unit is further configured to generate the output based on the identified extracted image (Kearney, 16:1-7) (see claim 1 for motivation to combine).
Regarding claim 6, and substantially claim 17, Jeyakumar in view of Kearney teaches the system of Claim 1. Kearney further teaches that the multimodal unit comprises an inference engine as a third sub-model and wherein the inference engine is configured to infer and identify an image within the received electronic message (Kearney, 15:57-59, "The image classification model 1120 may process images 1160 through convolutional layers 1162 to fully connected layers 1164.", 16:1-7) (see claim 1 for motivation to combine).
Regarding claim 7 and substantially claim 18, Jeyakumar in view of Kearney teaches the system of Claim 1, wherein the multimodal unit comprises an aggregator/classifier unit configured to generate the output from the at least two sub- models by running a classification layer (Jeyakumar, ¶62, "the third model 210 can aggregate the outputs produced by the models in the ensemble, characterize the attack based on the aggregated outputs,", a third model aggregates the outputs of the models in the ensemble (multimodal unit) to characterize the attack (classify it). ¶94, "The output(s) produced by the analysis module(s) 312 can optionally be fed into a master detector that analyzes these output(s) in order to produce a final classification for the communication as an attack or non-attack, as shown in FIG. 6.").
Regarding claim 8 and substantially claim 19, Jeyakumar in view of Kearney teaches the system of Claim 1, wherein the multimodal unit is further configured to store data associated with the received electronic message in the database in response to accuracy of the output exceeding a threshold (Jeyakumar, ¶138, the output of the models is compared with a threshold to determine classification of an email as malicious or not. ¶163-¶164, each entity determined to be malicious has information related to the message such as IP addresses and domains uploaded to the database as signatures of malicious attackers for later protection).
Regarding claim 9 and substantially claim 20, Jeyakumar in view of Kearney teaches the system of Claim 1, wherein the cybersecurity threat is one of a phishing attack or spam (Jeyakumar, ¶17, the type of attack that is identifier and responded to include phishing attacks).
Regarding claim 10 and substantially claim 21, Jeyakumar in view of Kearney teaches the system of Claim 1, wherein the received electronic message is one of an email message, an instant message, a social media message, or a social media post (Jeyakumar, ¶16, ¶17, the vector of the attack is an email).
Regarding claim 12, and substantially claim 23, Jeyakumar in view of Kearney teaches the system of Claim 1, wherein the multimodal unit applies a machine learning (ML) model to generate the output (Jeyakumar, ¶62, "the third model 210 can aggregate the outputs produced by the models in the ensemble, characterize the attack based on the aggregated outputs, and then convert the aggregated outputs into an explainable insight". ¶64, the model are machine-learning models such as logistic regression and deep learning models. ¶94, the multimodal unit uses a master detector that analyses the outputs to generate a final output).
Claim(s) 2, 5, 14, and 16 is/are rejected under 35 U.S.C. 103 as being unpatentable over Jeyakumar in view of Kearney as applied to claims 1 and 13 above, and further in view of Lee (Lee et al., US 20220094713 A1, cited in a prior office action).
Regarding claim 2 and substantially claim 14, Jeyakumar in view of Kearney teaches the system of Claim 1. Jeyakumar in view of Kearney does not teach but, in an analogous art, Lee teaches that the contextual data analysis unit generates the context analysis data using a natural language processing (¶9, ¶14, ¶48, ¶69, NLP analysis creates the classification/identification of an email as malicious or non-malicious (categories, second type of data, contextual analysis data) based on extracted contextual data from fields such as the subject or body text).
It would be obvious to one of ordinary skill prior to the effective filing date of the claimed invention to modify Jeyakumar in view of Kearney using Lee to generate the context analysis data using a natural language processing because transformer models such as BERT can perform a wide variety of NLP tasks to classify malicious messages and can be compressed to become small and efficient (Lee, ¶89, ¶90).
Regarding claim 5 and substantially claim 16, Jeyakumar in view of Kearney teaches the system of Claim 1. Jeyakumar in view of Kearney does not teach but, in an analogous art, Lee teaches that the contextual data analysis unit uses at least one transformer model that is configured to create a representation of the received electronic message (¶54, ¶101, "The classification task may include a classification of maliciousness of messages, an identification of phishing email messages, or any other security classification task or the like. The model and/or the second model may include a Bidirectional Encoder Representation from Transformers model,").
It would be obvious to one of ordinary skill prior to the effective filing date of the claimed invention to modify Jeyakumar in view of Kearney using Lee to use a transformer model to create a representation of the received electronic message because transformer models such as BERT can perform a wide variety of NLP tasks to classify malicious messages and can be compressed to become small and efficient (Lee, ¶89, ¶90).
Claim(s) 11 and 22 is/are rejected under 35 U.S.C. 103 as being unpatentable over Jeyakumar in view of Kearney as applied to claims 1 and 13 above, and further in view of Cai (Cai et al., US 20110060983 A1, cited in a prior office action).
Regarding claim 11 and substantially claim 22, Jeyakumar in view of Kearney teaches the system of Claim 1. Jeyakumar in view of Kearney does not teach the rest of claim 11. In an analogous art, Cai teaches that the contextual data analysis unit uses machine learning (ML) and that the contextual data analysis unit performs text classification, text similarity, text clustering, keywords extraction, and topics discovery to generate the context analysis data (¶21, "… At step 202 the process extracts topics and topic keywords from the collection of text documents. … The topics and topic keywords may be extracted from the collection of text documents using any known text analysis method. Examples of text analysis methods include text categorization techniques, text clustering techniques, latent semantic models…Examples of methods of determining importance ranking include (i) using a weighted mean and standard deviation of topic distributions, (ii) using Laplacian scores of topics, (iii) using pairwise mutual information of topics and (iv) using topic similarity between topics.", ¶41, "The Laplacian score of a topic focuses on discriminating documents from different classes. In other words, the Laplacian score method is motivated by the observation that two similar documents are probably related to the same topic", ¶23, the analysis is performed by a machine learning model).
It would be obvious to one of ordinary skill prior to the effective filing date of the claimed invention to modify Jeyakumar in view of Kearney using Cai to use text classification, text similarity, text clustering, keywords extraction, and topics discovery to generate the context analysis data because it may allow for the detection of fraud in emails (Cai, ¶21, "input a collection of text documents 101, such as a collection of email messages that was obtained during the discovery phase of a litigation matter… In the context of the litigation example, these topics may represent topics in conversations between victim and suspect, or topics that may incriminate a suspect in fraud… ").
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Goutte (Goutte et al., US 20060123083 A1) teaches OCRing a message to obtain image and text data within (¶18), analyzing its content to determine the context of the message (¶19), and coalescing it along with the IP address to categorize the message as spam or not (¶21-¶25, "Generally, each decision maker may work on a different data type and/or rely on different decision making principles (e.g., rule based or statistical based). Each decision maker of the categorizer 108, provides as output a message class for classifying the message data that is input to categorizer coalescer 110.")
Yanovsky (Yanovsky et al., US 9077671 B2) teaches extracting the IP address of an e-mail message, the content of the text of the message, embedded images of the message, etc. (4:65-5:7), as well as collecting statistical information with regards to IP addresses to via evaluations from other contributors (5:60-6:3).
Hall (US 20200314125 A1) teaches a multi-modal unit that implements multiple sub-model that utilize domain data and contextual analysis data to categorize an email (¶50, domain information, network addresses, file attachments, and message bodies are parsed from the email. ¶27, "For example, the analysis module 130a may be configured to process domain names, the analysis module 130b may be configured to process email addresses… In some implementations, some types of analysis modules may be configured to parse various types of attachments, such as text (*.TXT), binary (*.JPG, *.GIF, *.PNG, *.EXE), documents (*.DOC, *.PDF), and compressed files (*.zip, *.rar). In some implementations, some types of analysis modules may be configured to identify and analyze hyperlinks, physical addresses… For example, one or more of the analysis modules 130a-103n could be configured to enrich existing artifacts with contextual data by correlating them with internal and external cyber threat intelligence data. ". ¶53, "… identifying, based on the data type, an analysis module from a collection of predetermined analysis modules, where each of the analysis modules is configured to parse a predetermined data type". See also Fig. 1)
Young (Young et al., US 20220337623 A1) teaches executing a query against domain name databases to search for a pattern involving the domain name for a phishing operation and a machine learning algorithm that uses the data to determine whether the received communication is malicious or not (¶11, ¶39-¶40), where the machine learning model takes input as feature data including an IP address and contextual data regarding the communication (¶43)
Dimitriadis (Dimitriadis et al., US 20150058004 A1) teaches performing late fusion on a bunch of classifier (late fusion being an algorithm where a group of classifier classify an object on different fields, and a master model takes the classifications and makes a final judgment) (¶12, ¶21, ¶24), and discusses performing the system on emails to classify them as spam or not spam (¶16, "In another example, the system can classify emails as spam or non-spam based on features and output from classifiers regarding the content, context, or other attributes related to the email messages.")
Any inquiry concerning this communication or earlier communications from the examiner should be directed to AMIR MAHDI HAJIABBASI whose telephone number is (703)756-5511. The examiner can normally be reached M-F 7:30-5 EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Catherine Thiaw can be reached at (571) 270-1138. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/A.M.H./
Amir Mahdi Hajiabbasi Examiner, Art Unit 2407
/Catherine Thiaw/ Supervisory Patent Examiner, Art Unit 2407 8/18/2026