DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendment
The amendment filed 12 December 2025 has been entered. Applicant amended claims 1, 4-5, 8, 14-15, and 18-19. Accordingly, claims 1-20 remain pending.
Response to Arguments
Regarding the 35 USC 103 Rejection:
Applicant's arguments filed 12 December 2025 regarding the prior art does not teach “generate, without receiving a full copy of the at least one data record, a set of proposed remediations….” have been fully considered but they are not persuasive.
Examiner’s remarks:
Glynn reveals in the abstract and column 8, lines 35-44 generating the corresponding remediation action based on a scan on system of interest based on a plurality of configuration parameters. The system of interest entails a portion of the system’s data and not the full copy of the record in the system. Thus, the generated remediation is based on selected systems/data and not on a full copy of a data record.
Applicant’s arguments with respect to the remaining amended limitations in the independent claims have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1, 6-8, and 10-14 is/are rejected under 35 U.S.C. 103 as being unpatentable over Tumpic et al US 20220092086 (hereinafter Tumpic), in view of Glynn et US 10817611 (hereinafter Glynn), in further view of Bar-ness et al US 20250139238 (hereinafter Bar-ness), in further view of Clauson et al US 20240289470 (hereinafter Clauson), and in further view of Soby et al US 11418393 (hereinafter Soby).
As to claim 1, Tumpic teaches a system for data remediation (paragraph 16 discloses systems and methods for … remediation of sensitive data within large heterogeneous datasets of live services environments. Figure 1A-1B reveals the system architecture and Figure 7 discloses the hardware environment in which the method described with regard to the system in Figures 1A-1B is implemented, see also paragraph 61), the system comprising:
one or more memories (figure 7 and paragraph 61 disclose the storage device as reference number 750); and
one or more processors, communicatively coupled to the one or more memories (paragraph 61 and Figure 7 further disclose processor 770. Program code 760 stored in memory includes instructions that cause the processor 770 to perform the method described with regard to Figures 1A-1B), configured to:
receive, from a tracking system (figure 1A , reference number 60 “Content Intake System” is the tracing system), a set of tickets associated with at least one data record (paragraph 41 discloses an audit system receives content that is to be audited via the content intake system. The content to be audited may be from several sources such as a game server, a web server, a messaging server or source code repositories. The content received is the ticket that is based on sensitive data and other defined criteria. A ticket can be a document/notification of records);
search, in the at least one data record and using a set of contexts indicated in the set of tickets, for a set of sensitive data snippets (paragraph 42 discloses the content (from the several sources) is scanned using attention filters/rules and calculated culling filters such that the result set can include a high rate of true positive data items and a high recall rate and a risk assessment is performed in which context is extracted when the attention filter finds a match. A risk identifier can also be assigned to the finding (e.g., data snippet containing a data item). The searching method is further described in paragraphs 50-53, wherein paragraph 50 discloses the process allows the user to find a data item from the content/ticket (such as a password-therefore the sensitive data snippet pertains to password) that match a defined criterion/context in a large dataset. The dataset can include a large amount of data such as source code, for example stored on a data-centre. The dataset includes a plurality of data snippets, and a data snippet has a data item and a context of the data item (e.g., features in the vicinity of the data item));
output, for each sensitive data snippet in the set of sensitive data snippets, a corresponding proposed remediation in the set of proposed remediations (paragraphs 43 and 49 disclose a report about the results [ thus corresponds to each of the sensitive data snippets] is sent to stakeholders and a remediation is performed in which the stakeholders are enabled to remediate the found data items (in the source code, text, chat . . . ));
[performed] remediations corresponding to the set of sensitive data snippets (paragraphs 43 and 49 disclose a report about the results [ thus corresponds to each of the sensitive data snippets] is sent to stakeholders and a remediation is performed in which the stakeholders are enabled to remediate the found data items (in the source code, text, chat . . . )).
Tumpic does not teach generate, without receiving a full copy of the at least one data record, a set of proposed remediations corresponding to the set of sensitive data snippets and selectively apply the set of proposed remediations based on inputs from a user, wherein the one or more processors, to selectively apply the set of proposed remediations are configured to: write, in response to receiving an input indicating acceptance of a first proposed remediation in the set of proposed remediation, the first proposed remediation directly to the at least one data record at a data source hosting the at least one data record.
Glynn teaches generate, without receiving a full copy of the at least one data record (abstract and column 8, lines 35-44 disclose generating corresponding remediation action based on a scan on system of interest based on a plurality of configuration parameters. Thus, the generated remediation is based on selected systems/data and not on a full copy of a data record), a set of proposed remediations corresponding to the set of [findings that pertains to risks] (column 8, lines 23-63 disclose once the scan is completed, the finding results is sent to the detection system, at which the detection system directs the finds to a remediation management framework. The remediation management framework determines if any of the findings trigger a remediation action based on the policies. If any of the findings do trigger a remediation action, then remediation system and tools generate a corresponding/proposed remediation action. The remediation action may be defined by the predetermined policies and may include a variety of actions, for example, sending an email with the desired actions to be performed, or turn off a server, or upload a patch, or any type of immediate or delayed action for a predetermined period of time). It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Tumpic’s system for data remediation with Glynn’s teachings of generating proposed remediation to provide a system that automates software systems remediations while improving software integrity and stability (column 1, lines 6-9 of Glynn).
The combination of Tumpic in view of Glynn does not teach the proposed remediations corresponding to the set of sensitive data results/snippets and selectively apply the set of proposed remediations based on inputs from a user, wherein the one or more processors, to selectively apply the set of proposed remediations are configured to: write, in response to receiving an input indicating acceptance of a first proposed remediation in the set of proposed remediation, the first proposed remediation directly to the at least one data record at a data source hosting the at least one data record.
Bar-ness teaches the proposed remediations corresponding to the set of sensitive data results/snippets (paragraphs 41 and 46 disclose the bypass detector generates a signal to cause a remediation action to be generated that corresponds to detected sensitive information results/snippets) and selectively apply the set of proposed remediations based on inputs from a user (paragraphs 45 and 70 disclose the remediation action executor is configured to select/execute one or more remediation actions from remediation lists based on user input).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Tumpic’s system for data remediation in view Glynn’s teachings of generating proposed remediation with Bar-ness’s remediation list and selection of the remediation action to maintain the sensitivity of PII data and prevent unauthorize individuals from viewing the sensitive data (paragraph 15 of Bar-ness).
The combination of Tumpic in view of Glynn and Bar-ness does not teach wherein the one or more processors, to selectively apply the set of proposed remediations are configured to: write, in response to receiving an input indicating acceptance of a first proposed remediation in the set of proposed remediation, the first proposed remediation directly to the at least one data record at a data source hosting the at least one data record.
Clauson teaches wherein one or more processor (paragraphs 96-97 disclose processor performs the instructions stored in memory), to selectively apply the set of proposed remediation are configured to: [track], in response to receiving an input indicating acceptance of a first proposed remediation in the set of proposed remediation, the first proposed remediation (paragraphs 70-71 disclose the user interface associated with the UAR application is used to receive a remediation action selection and in response, the UAR manager perform remediation tracking).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Tumpic’s system for data remediation in view Glynn’s teachings of generating proposed remediation and Bar-ness’s remediation list and selection of the remediation action with Clauson’s teachings of receiving input of remediation selection and tracking such that a confirmation is providing that the remediation action is performed (paragraph 70 of Clauson).
The combination of Tumpic in view of Glynn, Bar-ness, and Clauson does not teach, but Soby teaches write, in response to receiving an input indicating acceptance of a first proposed remediation in the set of proposed remediation (column 9, lines 24-35 discloses receiving a user input commitment for completing the remediation step), the first proposed remediation directly to the at least one data record at a data source hosting the at least one data record (column 9, lines 58+ to column 10, lines 1-7 reveal as remediation engine performs events associated with either automatic or manual (thus selected) remediation for a violation, the audit log engine is configured to record each such event in the audit log/data record. A remediation event that is record in the audit log is maintain in the information storage, wherein column 8, lines 6-25 reveals the information storage/data source host the at least data audit log).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Tumpic’s system for data remediation in view Glynn’s teachings of generating proposed remediation, Bar-ness’s remediation list and selection of the remediation action, and Clauson’s teachings of receiving input of remediation selection and tracking with Soby’s teachings of recording the first proposed remediation such that the record/audit log can be viewed to inform accurately a viewing user the issue and how the issue was resolve (column 10, lines 5-7 of Soby).
As to claim 6, the combination of Tumpic in view of Glynn, Bar-ness, Clauson, and Soby teaches wherein the one or more processors (Tumpic: paragraph 61 and Figure 7 further disclose processor 770. Program code 760 stored in memory includes instructions that cause the processor 770 to perform the method described with regard to Figures 1A-1B), to search for the set of sensitive data snippets (Tumpic: paragraph 42 as disclosed above in claim 1), are configured to: identify a set of data types corresponding to the set of tickets and apply one or more rules associated with the set of data types to the at least one data record (Tumpic: paragraph 42 discloses the content is scanned using attention filters/rules and calculated culling filters such that the result set can include a high rate of true positive data items and a high recall rate and a risk assessment is performed in which context is extracted when the attention filter finds a match. A risk identifier can also be assigned to the finding (e.g., data snippet containing a data item). The searching method is further described in paragraphs 50-53, wherein paragraph 50 discloses the process allows the user to find a data item (such as a password) that match a defined criterion[data type] in a large dataset. The dataset can include a large amount of data such as source code, for example stored on a data-centre. The dataset includes a plurality of data snippets, and a data snippet has a data item and a context of the data item (e.g., features in the vicinity of the data item)).
As to claim 7, the combination of Tumpic in view of Glynn, Bar-ness, Clauson, and Soby teaches wherein the one or more processors (Tumpic: paragraph 61 and Figure 7 disclose processor 770. Program code 760 stored in memory includes instructions that cause the processor 770 to perform the method described with regard to Figures 1A-1B), to search for the set of sensitive data snippets (Tumpic: paragraph 42 as disclosed above in claim 1), are configured to: provide the set of contexts to a machine learning model in order to receive an indication of the set of sensitive data snippets (Tumpic: paragraph 42 discloses the content is scanned using attention filters/rules and calculated culling filters such that the result set can include a high rate of true positive data items and a high recall rate and a risk assessment is performed in which context is extracted when the attention filter finds a match. Paragraphs 51-52 disclose the data snippets are found using attention rules wherein one of the rules utilizes culling rules which is calculated using decision tree learning methods).
As to claim 8, Tumpic teaches a method of data remediation (paragraph 16 discloses systems and method for … remediation of sensitive data within large heterogeneous datasets of live services environments. Figure 1A-1B reveals the system architecture and Figure 7 discloses the hardware environment in which the method described with regard to the system in Figures 1A-1B is implemented, see paragraph 61) comprising:
receiving, at a remediation system from a tracking system (Figure 1A , reference number 60 “Content Intake System” is the tracing system), a set of tickets associated with a plurality of data records (paragraph 41 discloses an audit system receives content that is to be audited via the content intake system. The content to be audited may be from several sources such as a game server, a web server, a messaging server or source code repositories. The content is the ticket that is based on sensitive data and other defined criteria. A ticket is merely a document/notification that records or gives instructions);
searching, in the plurality of data records and using a set of contexts indicated in the set of tickets, for a set of sensitive data snippets (paragraph 42 discloses the content is scanned using attention filters/rules and calculated culling filters such that the result set can include a high rate of true positive data items and a high recall rate and a risk assessment is performed in which context is extracted when the attention filter finds a match. A risk identifier can also be assigned to the finding (e.g., data snippet containing a data item). The searching method is further described in paragraphs 50-53, wherein paragraph 50 discloses the process allows the user to find a data item (such as a password-therefore the sensitive data snippet pertains to password) that match a defined criterion in a large dataset. The dataset can include a large amount of data such as source code, for example stored on a data-centre. The dataset includes a plurality of data snippets, and a data snippet has a data item and a context of the data item (e.g., features in the vicinity of the data item));
determining, by the remediation system, that the set of sensitive data snippets are related (paragraphs 42 and 51 disclose the data snippets that are found based on the attention rules are categorized into different buckets such that all data snippets that are similar are grouped in the same bucket);
outputting, from the remediating system and to a user, the single proposed remediation (paragraphs 43 and 49 disclose a report about the found data[ thus corresponds to each of the data snippets] is sent to stakeholders and a remediation is performed in which the stakeholders are enabled to remediate the found data items (in the source code, text, chat . . . ));
[performing/executing the] remediation corresponding to the set of sensitive data snippets (paragraphs 43 and 49 disclose a report about the found data is sent to stakeholders and a remediation is performed in which the stakeholders are enabled to remediate the found data items (in the source code, text, chat . . . ). Thus, the remediation decision has been generated).
Tumpic does not teach generating, by the remediation system and without receiving full copies of the plurality of data records, a single proposed remediation corresponding to the set of sensitive data snippets and selectively apply the single proposed remediations to the plurality of data records in response to a single input from the user indicating acceptance of the single proposed remediation, wherein selectively applying the single proposed remediation to the plurality of data records comprises: writing the single proposed remediation to at least one of the plurality of data records at a data source hosting the at least one of the plurality of data records.
Glynn teaches generating, by the remediation system and without receiving full copies of the plurality of data records (abstract and column 8, lines 35-44 disclose generating corresponding remediation action based on a scan on system of interest based on a plurality of configuration parameters. Thus, the generated remediation is based on selected systems/data and not on a full copy of a data record), a single proposed remediation corresponding to the set of [findings that pertains to risks] (column 8, lines 23-63 disclose once the scan is completed, the finding results is sent to the detection system, at which the detection system directs the finds to a remediation management framework. The remediation management framework determines if any of the findings trigger a remediation action based on the policies. If any of the findings do trigger a remediation action, then remediation system and tools generate a corresponding/proposed remediation action. The remediation action may be defined by the predetermined policies and may include a variety of actions, for example, sending an email with the desired actions to be performed, or turn off a server, or upload a patch, or any type of immediate or delayed action for a predetermined period of time). It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Tumpic’s system for data remediation with Glynn’s teachings of generating proposed remediation to provide a system that automates software systems remediations while improving software integrity and stability (column 1, lines 6-9 of Glynn).
The combination of Tumpic in view of Glynn does not teach the proposed remediation corresponding to the set of sensitive data results/snippets and selectively apply the single proposed remediations to the plurality of data records in response to a single input from the user indicating acceptance of the single proposed remediation, wherein selectively applying the single proposed remediation to the plurality of data records comprises: writing the single proposed remediation to at least one of the plurality of data records at a data source hosting the at least one of the plurality of data records.
Bar-ness teaches the proposed remediation corresponding to the set of sensitive data results/snippets (paragraphs 41 and 46 disclose the bypass detector generates a signal to cause a remediation action to be generated that corresponds to detected sensitive information results/snippets) and selectively apply the single proposed remediations to the plurality of data records based on a single input from the user (paragraphs 45 and 70 disclose the remediation action executor is configured to select one or more remediation actions from remediation lists based on user input).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Tumpic’s system for data remediation in view Glynn’s teachings of generating proposed remediation with Bar-ness’s remediation list and selection of the remediation action to maintain the sensitivity of PII data and prevent unauthorize individuals from viewing the sensitive data (paragraph 15 of Bar-ness).
The combination of Tumpic in view of Glynn and Bar-ness does not teach selectively apply the single proposed remediations … in response to a single input from the user indicating acceptance of the single proposed remediation, wherein selectively applying the single proposed remediation to the plurality of data records comprises: writing the single proposed remediation to at least one of the plurality of data records at a data source hosting the at least one of the plurality of data records.
Clauson teaches selectively apply the single proposed remediations … in response to a single input from the user indicating acceptance of the single proposed remediation, wherein selectively applying the single proposed remediation to the plurality of data records comprises: writing the single proposed remediation(paragraphs 70-71 disclose the user interface associated with the UAR application is used to receive a remediation action selection and in response, the UAR manager perform remediation tracking).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Tumpic’s system for data remediation in view Glynn’s teachings of generating proposed remediation and Bar-ness’s remediation list and selection of the remediation action with Clauson’s teachings of receiving input of remediation selection and tracking such that a confirmation is providing that the remediation action is performed (paragraph 70 of Clauson).
The combination of Tumpic in view of Glynn, Bar-ness, and Clauson does not teach, but Soby teaches writing the single proposed remediation to at least one of the plurality of data records at a data source hosting the at least one of the plurality of data records (column 9, lines 24-35 discloses receiving a user input commitment for completing the remediation step), the first proposed remediation directly to the at least one data record at a data source hosting the at least one data record (column 9, lines 58+ to column 10, lines 1-7 reveal as remediation engine performs events associated with either automatic or manual (thus selected) remediation for a violation, audit log engine configured to record each such event in the audit log/data record. A remediation event that is record in the audit log is maintain in the information storage, wherein column 8, lines 6-25 reveals the information storage/data source host the at least data audit log).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Tumpic’s system for data remediation in view Glynn’s teachings of generating proposed remediation, Bar-ness’s remediation list and selection of the remediation action, and Clauson’s teachings of receiving input of remediation selection and tracking with Soby’s teachings of recording the first proposed remediation such that the record/audit log can be viewed to inform accurately a viewing user the issue and how the issue was resolve (column 10, lines 5-7 of Soby).
As to claim 10, the combination of Tumpic in view of Glynn, Bar-ness, Clauson, and Soby teaches wherein determining that the set of sensitive data snippets are related (Tumpic: paragraphs 42 and 51) comprises: determining, by the remediation system, that one sensitive data snippet, in the set of sensitive data snippets, matches another sensitive data snippet in the set of sensitive data snippets (Tumpic: paragraph 42 discloses the content is scanned using attention filters/rules and calculated culling filters such that the result set can include a high rate of true positive data items and a high recall rate and a risk assessment is performed in which context is extracted when the attention filter finds a match. A risk identifier can also be assigned to the finding (e.g., data snippet containing a data item). The searching method is further described in paragraphs 50-53, wherein paragraph 50 discloses the process allows the user to find a data item (such as a password) that match a defined criterion[data type] in a large dataset. Paragraph 51 disclose the data snippets that are found based on the attention rules are categorized into different buckets such that all data snippets that are similar are grouped in the same bucket using SSDeep learning).
As to claim 11, the combination of Tumpic in view of Glynn, Bar-ness, Clauson, and Soby teaches wherein determining that the set of sensitive data snippets are related (Tumpic: paragraphs 42 and 51) comprises: determining, by the remediation system, that a difference between one context, in the set of contexts, and another context, in the set of contexts, satisfies a similarity threshold (Tumpic: paragraph 42 discloses the content is scanned using attention filters/rules and calculated culling filters such that the result set can include a high rate of true positive data items and a high recall rate and a risk assessment is performed in which context is extracted when the attention filter finds a match. Paragraph 51 disclose the data snippets that are found based on the attention rules are categorized into different buckets such that all data snippets that are similar are grouped in the same bucket using SSDeep learning. The buckets that do not contain data items (and context) are classified as false positives. Paragraph 38 discloses when SSDeep is applied to data snippets, then snippets that are similar end up in the same bucket. SSDeep creates a hash value that determines a level of similarity between two files. In other words, SSDeep is a fuzzy hashing algorithm which employs a similarity digest in order to determine whether the hashes that represent two files have similarities. If the hashes have similarities, then the original files can be assumed to be similar, too. For example, if a single byte of a file is manipulated, the SSDeep hashes of the original file and the manipulated file will be similar. SSDeep similarity scores range from zero (e.g., no similarity or hardly any similarity) to 100 (e.g., very similar or identical). See also paragraph 35).
As to claim 12, the combination of Tumpic in view of Glynn, Bar-ness, Clauson, and Soby teaches wherein outputting the single proposed remediation comprises: outputting instructions for a user interface (UI) including an indication of the single proposed remediation and an indication of at least one context in the set of contexts (Tumpic: paragraphs 43 and 49 disclose a report about the found data[ thus corresponds to each of the data snippets] is output and sent to stakeholders and a remediation is performed in which the stakeholders are enabled to remediate the found data items (in the source code, text, chat … ). Glynn: column 6, lines 33-42 discloses a detection remediation framework API communicates with detection system to receive the results of its scanning of system of interest to identify any risks. Detection remediation framework, after receiving the identified risks on system of interest , determines the appropriate remediation to be performed on system of interest. Bar-ness: paragraph 58 discloses the operation of remediation action executor may be configured manually and/or automatically (e.g., via a configuration portal or other interface), such as the timeout period and/or the remediation actions to perform (e.g., notification methods) under various types of circumstances (thus indicating the context)). Motivation is similar to the motivation presented in claim 8.
As to claim 13, the combination of Tumpic in view of Glynn, Bar-ness, Clauson, and Soby teaches receiving the single input from the user based on interactions with the UI (Tumpic: paragraphs 43 and 49 disclose a report about the found data[ thus corresponds to each of the data snippets] is output and sent to stakeholders and a remediation is performed in which the stakeholders are enabled to remediate the found data items (in the source code, text, chat . . . ). Bar-ness: paragraphs 45 and 70 disclose the remediation action executor is configured to select one or more remediation actions from remediation lists based on user input (thus a user is utilizes an interface)). Motivation is similar to the motivation presented in claim 8.
As to claim 14, the combination of Tumpic in view of Glynn and Bar-ness teaches further comprising: receiving the set of sensitive data snippets from a data source associated with the plurality of data records (Tumpic: abstract and paragraph 30 disclose identifying data snippets of the dataset using one or more rules. Paragraph 28 discloses dataset includes a variety of data snippets. A dataset can be of any size, including as described in some example embodiments herein gigabytes and terabytes of data. A data snippet has a length larger than a data item such that it additionally contains context of or relating to the data item.).
Claim(s) 2-3 is/are rejected under 35 U.S.C. 103 as being unpatentable over Tumpic et al US 20220092086 (hereinafter Tumpic), in view of Glynn et US 10817611 (hereinafter Glynn), in further view of Bar-ness et al US 20250139238 (hereinafter Bar-ness), in further view of Clauson et al US 20240289470 (hereinafter Clauson), in further view of Soby et al US 11418393 (hereinafter Soby), in further view of Gaurav et al US 10089202 (hereinafter Gaurav), and in further view of Izard et al US 20190116111 (hereinafter Izard)
As to claim 2, the combination of Tumpic in view of Glynn, Bar-ness, Clauson, and Soby teaches all the limitations recited in claim 1 above and further teaches sensitive data snippets (see claim 1 rejection above, paragraph 42: such as a password-therefore the sensitive data snippet pertains to password) and selectively applying the set of proposed remediations ( Bar-ness: paragraphs 45 and 70 disclose the remediation action executor is configured to select/execute one or more remediation actions from remediation lists based on user input).
The combination of Tumpic in view of Glynn, Bar-ness, Clauson, and Soby does not teach wherein the set of [data snippets] are temporarily loaded in the one or more memories after searching and are removed from the one or more memories after selectively applying [proposed remediation(s)].
Gaurav teaches wherein the set of [data snippets] are temporarily loaded in the one or more memories and are removed from the one or more memories after selectively applying [proposed remediation(s)] (column 9, lines 37-42 reveal the concept of a user taking remedial action, and further deletion of a snippet/snapshot from the storage space which was previously stored in the storage space).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Tumpic’s system for data remediation in view Glynn’s teachings of generating proposed remediation, Bar-ness’ remediation list and selection of the remediation action, Clauson’s teachings of receiving input of remediation selection and tracking, and Soby’s teachings of recording the first proposed remediation with Gaurav’s teachings of deletion of the snapshot/snippet that is stored in memory to free up space in the storage, thus ensuring that the storage space maintain high availability of storage space (column 9, lines 37-42 of Gaurav).
The combination of Tumpic in view of Glynn, Bar-ness, Clauson, Soby and Gaurav does not teach, but Izard teaches wherein the set of snippets are temporarily loaded in the one or more memories after searching and are removed from the one or more memories (paragraph 127 discloses that after being read and queried by the controller (thus loaded by the controller for reading) , the packet in storage is deleted).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Tumpic’s system for data remediation in view Glynn’s teachings of generating proposed remediation, Bar-ness’ remediation list and selection of the remediation action, Clauson’s teachings of receiving input of remediation selection and tracking, Soby’s teachings of recording the first proposed remediation and Gaurav’s teachings of deletion of the snapshot/snippet that is stored in memory with further Izard’s teachings of deletion of the data packet/snippet after being queried such that the system provides sufficient storage space for new packets/snippets (paragraph 127 of Izard).
As to claim 3, the combination of Tumpic, Glynn, Bar-ness, Clauson, Soby, Gaurav, and Izard teaches wherein the at least one data record is stored remotely from the system (Tumpic: Figure 1A and paragraph 41 reveal the retrieve content items are from the remote gamer server 10, web server 20, messaging server 30, and/or source code repositories 40. The remote gamer server 10, web server 20, messaging server 30, and/or source code repositories 40 are remote from the content intake 60 and audit 70 systems).
Claim(s) 4 is/are rejected under 35 U.S.C. 103 as being unpatentable over Tumpic et al US 20220092086 (hereinafter Tumpic), in view of Glynn et US 10817611 (hereinafter Glynn), in further view of Bar-ness et al US 20250139238 (hereinafter Bar-ness), in further view of Clauson et al US 20240289470 (hereinafter Clauson), in further view of Soby et al US 11418393 (hereinafter Soby), and in further view of Srivastava US 20200336508 (hereinafter Srivastava).
As to claim 4, the combination of Tumpic in view of Glynn, Bar-ness, Clauson, and Soby teaches all the limitations recited in claim 1 above and further teaches wherein the one or more processors to (Tumpic: paragraph 61 and Figure 7 further disclose processor 770. Program code 760 stored in memory includes instructions that cause the processor 770 to perform the method described with regard to Figures 1A-1B):
The combination of Tumpic in view of Glynn, Bar-ness, Clauson, and Soby does not teach but Srivastava teaches transmit at least one command to the tracking system to clear the set of tickets (paragraph 39 discloses application server perform remediation and perform/manage proactive security risk mitigation task management service and notification service. The task management service/tracking system enables task management including adding, removing/clearing [based on command], or editing one or more tasks/tickets and task properties and task lifecycle management. The notification service allows for deleting an old notification/ticket, editing details of the new or old notification).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Tumpic’s system for data remediation in view Glynn’s teachings of generating proposed remediation, Bar-ness’ remediation list and selection of the remediation action, Clauson’s teachings of receiving input of remediation selection and tracking, and Soby’s teachings of recording the first proposed remediation with Anthony’s teachings of sending the command to remote storage for applying the remediation to provide an improved systems and method for collecting the data, analyzing the data, and performing remedial actions while reducing communication latencies and processing power within the operational environment (paragraph 3 of Anthony).
Claim(s) 5 is/are rejected under 35 U.S.C. 103 as being unpatentable over Tumpic et al US 20220092086 (hereinafter Tumpic), in view of Glynn et US 10817611 (hereinafter Glynn), in further view of Bar-ness et al US 20250139238 (hereinafter Bar-ness), in further view of Clauson et al US 20240289470 (hereinafter Clauson), in further view of Soby et al US 11418393 (hereinafter Soby), and in further view of Bezdedeanu et al WO 2019018316 (hereinafter Bezdedeanu).
As to claim 5, the combination of Tumpic in view of Glynn, Bar-ness, Clauson, and Soby teaches all the limitation recited in claim 1 above and further teaches store a false positive indicator associated with the second proposed remediation in response to the rejection (Tumpic: paragraphs 46 and 49 disclose audit results are stored in such a way that they include context for further mapping and clustering of findings such that duplication is minimized and introduction tracing is possible. The audit results (paragraphs 45-46 reveal the audit results includes identifying false positives ) as a result of the result mapping are analyzed and remediation is performed by the user to remediate the found data items. Thus there is the rejection by the user of the remediation for false positives) and second proposed remediated in the set of proposed remediations (Bar-ness: paragraphs 45 and 70 disclose one or more remediation actions from remediation lists).
The combination of Tumpic in view of Glynn, Bar-ness, Clauson, and Soby does not teach, but Bezdedeanu teaches receiving, from the user, a rejection of a second proposed remediated (column 6, lines 35-36 disclose the concept of a user rejecting the potential remediation change).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Tumpic’s system for data remediation in view Glynn’s teachings of generating proposed remediation, Bar-ness’s remediation list and selection of the remediation action, Clauson’s teachings of receiving input of remediation selection and tracking, and Soby’s teachings of recording the first proposed remediation with Bezdedeanu’s teachings of the system receiving a rejection of the remediation to provide the ability for users to approve or disapprove potential remedial changes which bypasses the usual writing of data to persistent storage for potential remedial changes, such that the potential remedial changes do not automatically get committed to persistent storage at the next consistency point (column 6, lines 23-32 of Bezdedeanu).
Claim(s) 9, 15-17, and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Tumpic et al US 20220092086 (hereinafter Tumpic), in view of Glynn et US 10817611 (hereinafter Glynn), in further view of Bar-ness et al US 20250139238 (hereinafter Bar-ness), in further view of Clauson et al US 20240289470 (hereinafter Clauson), in further view of Soby et al US 11418393 (hereinafter Soby), in further view of Cheng et al US 20230403218 (hereinafter Cheng), and in further view of Waldo et al US 20210224704 (hereinafter Waldo).
As to claim 9, the combination of Tumpic in view of Glynn, Bar-ness, Clauson, and Soby teaches all the limitations recited in claim 8 above and further teaches selectively applying the single proposed remediation (Bar-ness: paragraphs 45 and 70 disclose the remediation action executor is configured to select/execute one or more remediation actions from remediation lists based on user input).
The combination of Tumpic in view of Glynn, Bar-ness, Clauson, and Soby does not teach further comprising: transmitting, to the tracking system, a set of commands to clear the set of tickets based on selectively applying the single proposed remediation.
Cheng teaches further comprising: transmitting, to the tracking system, a set of commands to clear the set of tickets (paragraph 90 reveals the concept of said limitation disclosing sending a call/command to the transport node/tracking system (the transport node which is the forwarder/controller or Host-A (see paragraph 45) of the Control Plane (see Figure 2 ) to delete stale configuration records (that pertains to state information). The controller on the control plane includes a collector and remediation unit that track state information. A ticket is merely a document/notification that records or gives instructions).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Tumpic’s system for data remediation in view Glynn’s teachings of generating proposed remediation, Bar-ness’s remediation list and selection of the remediation action, Clauson’s teachings of receiving input of remediation selection and tracking, and Soby’s teachings of recording the first proposed remediation with Cheng’s teaching of sending a set of commands to clear a set of tickets to prevent incorrect reading of the ticket and unwanted network behavior, which is undesirable and affects network performance (paragraph 2 of Cheng).
The combination of Tumpic in view of Glynn, Bar-ness, Clauson, Soby, and Cheng does not teach, but Waldo teaches clearing the set of tickets based on selectively applying the single proposed remediation (paragraphs 53 and 81 disclose concept of deleting report/tickets once remedial action is applied).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Tumpic’s system for data remediation in view Glynn’s teachings of generating proposed remediation. Bar-ness’s remediation list and selection of the remediation action, Clauson’s teachings of receiving input of remediation selection and tracking, Soby’s teachings of recording the first proposed remediation, and Cheng’s teaching of sending a set of commands to clear a set of tickets with Waldo’s teachings of clearing tickets when a remediation is performed to reduce the digital footprint and to consistently analyze and validate data being collected, thus permitting accurate detection of any anomalies or errors being generated from its models and systems (paragraphs 7-8 of Waldo).
As to claim 15, Tumpic teaches a non-transitory computer readable medium storing a set of instructions (figure 7 and paragraph 61 disclose the storage device as reference number 750. Paragraph 61 and Figure 7 further disclose processor 770. Program code 760 stored in memory includes instructions that cause the processor 770 to perform the method described with regard to Figures 1A-1B) for data remediation (paragraph 16 discloses systems and methods for order independent categorization, identification, and remediation of sensitive data within large heterogeneous datasets of live services environments. Figure 1A-1B reveals the system architecture and Figure 7 discloses the hardware environment in which the method described with regard to the system in Figures 1A-1B is implemented, see paragraph 61), the set of instructions comprising:
one or more instructions that, when executed by one or more processors of a device cause the device to (paragraph 61 and Figure 7 further disclose processor 770. Program code 760 stored in memory includes instructions that cause the processor 770 to perform the method described with regard to Figures 1A-1B):
receive, from a tracking system (figure 1A , reference number 60 “Content Intake System” is the tracing system), a set of tickets associated with at least one data record (paragraph 41 discloses an audit system receives content that is to be audited via the content intake system. The content to be audited may be from several sources such as a game server, a web server, a messaging server or source code repositories. The content is the ticket that is based on sensitive data and other defined criteria. A ticket is merely a document/notification that records or gives instructions);
search, in the at least one data record and using a set of contexts indicated in the set of tickets, for a set of sensitive data snippets (paragraph 42 discloses the content is scanned using attention filters/rules and calculated culling filters such that the result set can include a high rate of true positive data items and a high recall rate and a risk assessment is performed in which context is extracted when the attention filter finds a match. A risk identifier can also be assigned to the finding (e.g., data snippet containing a data item). The searching method is further described in paragraphs 50-53, wherein paragraph 50 discloses the process allows the user to find a data item (such as a password) that match a defined criterion in a large dataset. The dataset can include a large amount of data such as source code, for example stored on a data-centre. The dataset includes a plurality of data snippets, and a data snippet has a data item and a context of the data item (e.g., features in the vicinity of the data item));
[performed] remediations corresponding to the set of sensitive data snippets (paragraphs 43 and 49 disclose a report about the found data is sent to stakeholders and a remediation is performed in which the stakeholders are enabled to remediate the found data items (in the source code, text, chat . . . )).
Tumpic does not teach generate, without receiving a full copy of the at least one data record, a set of proposed remediations corresponding to the set of sensitive data snippets; selectively apply the set of proposed remediations based on inputs from a user wherein the one or more instructions that cause the device to selectively apply the set of proposed remediations cause the device to: write, in response to receiving an input indicating acceptance of a first proposed remediation in the set of proposed remediation, the first proposed remediation directly to the at least one data record at a data source hosting the at least one data record; and transmit, to the tracking system, a set of commands to clear the set of tickets based on selectively applying the set of proposed remediations.
Glynn teaches generate, without receiving a full copy of the at least one data record (abstract and column 8, lines 35-44 disclose generating corresponding remediation action based on a scan on system of interest based on a plurality of configuration parameters. Thus, the generated remediation is based on selected systems/data and not on a full copy of a data record), a set of proposed remediations corresponding to the set of [findings that pertains to risks] (column 8, lines 23-63 disclose once the scan is completed, the finding results is sent to the detection system, at which the detection system directs the finds to a remediation management framework. The remediation management framework determines if any of the findings trigger a remediation action based on the policies. If any of the findings do trigger a remediation action, then remediation system and tools generate a corresponding/proposed remediation action. The remediation action may be defined by the predetermined policies and may include a variety of actions, for example, sending an email with the desired actions to be performed, or turn off a server, or upload a patch, or any type of immediate or delayed action for a predetermined period of time). It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Tumpic’s system for data remediation with Glynn’s teachings of generating proposed remediation to provide a system that automates software systems remediations while improving software integrity and stability (column 1, lines 6-9 of Glynn).
The combination of Tumpic in view of Glynn does not teach the proposed remediations corresponding to the set of sensitive data results/snippets; selectively apply the set of proposed remediations based on inputs from a user wherein the one or more instructions that cause the device to selectively apply the set of proposed remediations cause the device to: write, in response to receiving an input indicating acceptance of a first proposed remediation in the set of proposed remediation, the first proposed remediation directly to the at least one data record at a data source hosting the at least one data record;
; and transmit, to the tracking system, a set of commands to clear the set of tickets based on selectively applying the set of proposed remediations.
Bar-ness teaches the proposed remediations corresponding to the set of sensitive data results/snippets (paragraphs 41 and 46 disclose the bypass detector generates a signal to cause a remediation action to be generated that corresponds to detected sensitive information results/snippets) and selectively applying the set of proposed remediation (paragraphs 45 and 70 disclose the remediation action executor is configured to select one or more remediation actions from remediation lists based on user input).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Tumpic’s system for data remediation in view Glynn’s teachings of generating proposed remediation with Bar-ness’s remediation list and selection of the remediation action to maintain the sensitivity of PII data and prevent unauthorize individuals from viewing the sensitive data (paragraph 15 of Bar-ness).
The combination of Tumpic in view of Glynn and Bar-ness does not teach selectively apply the set of proposed remediations based on inputs from a user wherein the one or more instructions that cause the device to selectively apply the set of proposed remediations cause the device to: write, in response to receiving an input indicating acceptance of a first proposed remediation in the set of proposed remediation, the first proposed remediation directly to the at least one data record at a data source hosting the at least one data record; and transmitting, to the tracking system, a set of commands to clear the set of tickets based on selectively applying the single proposed remediation.
Clauson teaches wherein the one or more instructions (paragraphs 96-97 disclose processor performs the instructions stored in memory), that cause the device to selectively apply the set of proposed remediation, cause the device to: [track], in response to receiving an input indicating acceptance of a first proposed remediation in the set of proposed remediation, the first proposed remediation (paragraphs 70-71 disclose the user interface associated with the UAR application is used to receive a remediation action selection and in response, the UAR manager perform remediation tracking).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Tumpic’s system for data remediation in view Glynn’s teachings of generating proposed remediation and Bar-ness’s remediation list and selection of the remediation action with Clauson’s teachings of receiving input of remediation selection and tracking such that a confirmation is providing that the remediation action is performed (paragraph 70 of Clauson).
The combination of Tumpic in view of Glynn, Bar-ness, and Clauson does not teach write, in response to receiving an input indicating acceptance of a first proposed remediation in the set of proposed remediation, the first proposed remediation directly to the at least one data record at a data source hosting the at least one data record; and transmitting, to the tracking system, a set of commands to clear the set of tickets based on selectively applying the single proposed remediation.
Soby teaches write, in response to receiving an input indicating acceptance of a first proposed remediation in the set of proposed remediation (column 9, lines 24-35 discloses receiving a user input commitment for completing the remediation step), the first proposed remediation directly to the at least one data record at a data source hosting the at least one data record (column 9, lines 58+ to column 10, lines 1-7 reveal as remediation engine performs events associated with either automatic or manual (thus selected) remediation for a violation, audit log engine configured to record each such event in the audit log/data record. A remediation event that is record in the audit log is maintain in the information storage, wherein column 8, lines 6-25 reveals the information storage/data source host the at least data audit log).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Tumpic’s system for data remediation in view Glynn’s teachings of generating proposed remediation, Bar-ness’s remediation list and selection of the remediation action, and Clauson’s teachings of receiving input of remediation selection and tracking with Soby’s teachings of recording the first proposed remediation such that the record/audit log can be viewed to inform accurately a viewing user the issue and how the issue was resolve (column 10, lines 5-7 of Soby).
The combination of Tumpic in view of Glynn, Bar-ness, Clauson, and Soby does not teach transmitting, to the tracking system, a set of commands to clear the set of tickets based on selectively applying the single proposed remediation.
Cheng teaches further comprising: transmitting, to the tracking system, a set of commands to clear the set of tickets (paragraph 90 reveals the concept of said limitation disclosing sending a call/command to the transport node/tracking system (the transport node which is the forwarder/controller or Host-A (see paragraph 45) of the Control Plane (see Figure 2 ) to delete stale configuration records (that pertains to state information). The controller on the control plane includes a collector and remediation unit that track state information. A ticket is merely a document/notification that records or gives instructions).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Tumpic’s system for data remediation in view Glynn’s teachings of generating proposed remediation, Bar-ness’s remediation list and selection of the remediation action, Clauson’s teachings of receiving input of remediation selection and tracking, and Soby’s teachings of recording the first proposed remediation with Cheng’s teaching of sending a set of commands to clear a set of tickets to prevent incorrect reading of the ticket and unwanted network behavior, which is undesirable and affects network performance (paragraph 2 of Cheng).
The combination of Tumpic in view of Glynn, Bar-ness, Clauson, Soby, and Cheng does not teach, but Waldo teaches clearing the set of tickets based on selectively applying the single proposed remediation (paragraphs 53 and 81 disclose concept of deleting report/tickets once remedial action is applied).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Tumpic’s system for data remediation in view Glynn’s teachings of generating proposed remediation, Bar-ness’s remediation list and selection of the remediation action, Clauson’s teachings of receiving input of remediation selection and tracking, Soby’s teachings of recording the first proposed remediation and Cheng’s teaching of sending a set of commands to clear a set of tickets with Waldo’s teachings of clearing tickets when a remediation is performed to reduce the digital footprint and to consistently analyze and validate data being collected, thus permitting accurate detection of any anomalies or errors being generated from its models and systems (paragraphs 7-8 of Waldo).
As to claim 16, the combination of Tumpic in view of Glynn, Bar-ness, Clauson, Soby, Cheng, and Waldo teaches wherein the one or more instructions, when executed by the one or more processors, further cause the device to (Tumpic: paragraph 61 and Figure 7 further disclose processor 770. Program code 760 stored in memory includes instructions that cause the processor 770 to perform the method described with regard to Figures 1A-1B): receive the inputs from the user based on interaction with elements of a user interface that indicates the set of proposed remediations (Tumpic: paragraphs 43 and 49 disclose a report about the found data[ thus corresponds to each of the data snippets] is output and sent to stakeholders and a remediation is performed in which the stakeholders are enabled to remediate the found data items (in the source code, text, chat . . . ). Bar-ness: paragraphs 45 and 70 disclose the remediation action executor is configured to select one or more remediation actions from remediation lists based on user input). Motivation is similar to the motivation presented in claim 15.
As to claim 17, the combination of Tumpic in view of Glynn, Bar-ness, Clauson, Soby, Cheng, and Waldo teaches wherein the one or more instructions, that cause the device to (Tumpic: paragraph 61 and Figure 7 further disclose processor 770. Program code 760 stored in memory includes instructions that cause the processor 770 to perform the method described with regard to Figures 1A-1B):
search for the set of sensitive data snippets (Tumpic: paragraph 42 discloses the content is scanned using attention filters/rules and calculated culling filters such that the result set can include a high rate of true positive data items and a high recall rate and a risk assessment is performed in which context is extracted when the attention filter finds a match. A risk identifier can also be assigned to the finding (e.g., data snippet containing a data item). The searching method is further described in paragraphs 50-53, wherein paragraph 50 discloses the process allows the user to find a data item (such as a password) that match a defined criterion in a large dataset. The dataset can include a large amount of data such as source code, for example stored on a data-centre. The dataset includes a plurality of data snippets, and a data snippet has a data item and a context of the data item (e.g., features in the vicinity of the data item), cause the device to:
transmit, to a data source hosting the at least one data record, a set of queries based on the set of contexts (Tumpic: paragraphs 35 and 39 disclose queries are used in the search engines which utilizes fuzzy matching (SSDeep). The fuzzy matching allows the engine to return a pertinent search result even if there is a typing error in the query. The content from the data sources such as game server, web server, messaging server, and repositories are obtained and transferred to the content intake system, which in returns is submitted to the audit system for scanning/searching and filtering. The searching method is further described in paragraphs 50-53, wherein paragraph 50 discloses the process allows the user to find a data item (thus query a password) that match a defined criterion in a large dataset); and
receive, from the data source, the set of sensitive data snippets in response to the set of queries (Tumpic: paragraph 50 discloses the process allows the user to find a data item (such as a password) that match a defined criterion in a large dataset. The dataset can include a large amount of data such as source code, for example stored on a data-centre. The dataset includes a plurality of data snippets which is received by the result mapping audit system. A data snippet has a data item and a context of the data item (e.g., features in the vicinity of the data item)).
As to claim 20, the combination of Tumpic in view of Glynn, Bar-ness, Clauson, Soby, Cheng, and Waldo teaches wherein the one or more instructions, when executed by the one or more processors, further cause the device to (Tumpic: paragraph 61 and Figure 7 further disclose processor 770. Program code 760 stored in memory includes instructions that cause the processor 770 to perform the method described with regard to Figures 1A-1B):
receive a set of credentials associated with the user (Tumpic: paragraph 50 discloses the process allows the user to find a data item (thus query a password) that match a defined criterion in a large dataset); and
transmit, to the tracking system, a request including the set of credentials, wherein the set of tickets are received in response to the request (Tumpic: paragraph 50 discloses the process allows the user to find a data item (thus query a password) that match a defined criterion in a large dataset. Paragraphs 35 and 39 disclose queries are used in the search engines which utilizes fuzzy matching (SSDeep). The fuzzy matching allows the engine to return a pertinent search result even if there is a typing error in the query. The content from the data sources such as game server, web server, messaging server, and repositories are obtained and transferred to the content intake system, which in returns is submitted to the audit system for scanning/searching and filtering. The searching method is further described in paragraphs 50-53, wherein paragraph 50 discloses the process allows the user to find a data item (thus query a password) that match a defined criterion in a large dataset).
Claim(s) 18-19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Tumpic et al US 20220092086 (hereinafter Tumpic), in view of Glynn et US 10817611 (hereinafter Glynn), in further view of Bar-ness et al US 20250139238 (hereinafter Bar-ness), in further view of Clauson et al US 20240289470 (hereinafter Clauson), in further view of Soby et al US 11418393 (hereinafter Soby), in further view of Cheng et al US 20230403218 (hereinafter Cheng), in further view of Waldo et al US 20210224704 (hereinafter Waldo), and in further view of Bezdedeanu et al WO 2019018316 (hereinafter Bezdedeanu).
As to claim 18, the combination of Tumpic in view of Glynn, Bar-ness, Clauson, Soby, Cheng, and Waldo teaches all the limitation recited in claim 15 above and further teaches wherein the one or more instructions, that cause the device to (Tumpic: paragraph 61 and Figure 7 further disclose processor 770. Program code 760 stored in memory includes instructions that cause the processor 770 to perform the method described with regard to Figures 1A-1B): selectively apply the set of proposed remediation, cause the device to (Bar-ness: paragraphs 45 and 70 disclose the remediation action executor is configured to select/execute one or more remediation actions from remediation lists based on user input): store a false positive indicator associated with the second proposed remediation in response to the rejection (Tumpic: paragraphs 46 and 49 disclose audit results are stored in such a way that they include context for further mapping and clustering of findings such that duplication is minimized and introduction tracing is possible. The audit results (paragraphs 45-46 reveal the audit results includes identifying false positives ) as a result of the result mapping are analyzed and remediation is performed by the user to remediate the found data items. Thus there is the rejection by the user of the remediation for false positives) and at least one proposed remediated in the set of proposed remediations (Bar-ness: paragraphs 45 and 70 disclose one or more remediation actions from remediation lists).
The combination of Tumpic in view of Glynn, Bar-ness, Clauson, Soby, Cheng, and Waldo does not teach but Bezdedeanu teaches receiving, from the user, a rejection of a second proposed remediated (column 6, lines 35-36 disclose the concept of a user rejecting the potential remediation change).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Tumpic’s system for data remediation in view Glynn’s teachings of generating proposed remediation, Bar-ness’s remediation list and selection of the remediation action, Clauson’s teachings of receiving input of remediation selection and tracking, Soby’s teachings of recording the first proposed remediation, Cheng’s teaching of sending a set of commands to clear a set of tickets, and Waldo’s teachings of clearing tickets when a remediation is performed with Bezdedeanu’s teachings of the system receiving a rejection of the remediation to provide the ability for users to approve or disapprove potential remedial changes which bypasses the usual writing of data to persistent storage for potential remedial changes, such that the potential remedial changes do not automatically get committed to persistent storage at the next consistency point (column 6, lines 23-32 of Bezdedeanu).
As to claim 19, the combination of Tumpic in view of Glynn, Bar-ness, Clauson, Soby, Cheng, and Waldo teaches all the limitation recited in claim 15 above and further teaches wherein the one or more instructions, that cause the device to (Tumpic: paragraph 61 and Figure 7 further disclose processor 770. Program code 760 stored in memory includes instructions that cause the processor 770 to perform the method described with regard to Figures 1A-1B): selectively apply the set of proposed remediation, cause the device to (Bar-ness: paragraphs 45 and 70 disclose the remediation action executor is configured to select/execute one or more remediation actions from remediation lists based on user input): transmit a false positive indicator to a machine learning host associated with searching for the set of sensitive data snippets (Tumpic: abstract and paragraphs 34-35, 38 42 discloses the data snippets are categorized using fuzzy matching by assigning them to buckets such that each bucket contains data snippets that are similar to another according to a similarity measure. Buckets containing data snippets having more than a threshold number of the true positive data items are classified as true positive buckets and remaining buckets are classified as false positive buckets. Culling rules are calculated based on the true positive buckets and the false positive buckets. The culling rules are used to remove the false positive data items from the true positive buckets. Paragraph 34 further discloses fuzzy matching or machine learning process of SSDeep is used, wherein the result from the process is feed-back on itself so that the tool could constantly improve after each run. SSDeep is a ML algorithm) and at least one proposed remediated in the set of proposed remediations (Bar-ness: paragraphs 45 and 70 disclose one or more remediation actions from remediation lists).
The combination of Tumpic in view of Glynn, Bar-ness, Clauson, Soby, Cheng, and Waldo does not teach but Bezdedeanu teaches receiving, from the user, a rejection of a second proposed remediated (column 6, lines 35-36 disclose the concept of a user rejecting the potential remediation change).
It would have been obvious for one having ordinary skill in the art before the effective filing date of the claimed invention to modify Tumpic’s system for data remediation in view Glynn’s teachings of generating proposed remediation, Bar-ness’s remediation list and selection of the remediation action, Clauson’s teachings of receiving input of remediation selection and tracking, Soby’s teachings of recording the first proposed remediation, Cheng’s teaching of sending a set of commands to clear a set of tickets, and Waldo’s teachings of clearing tickets when a remediation is performed with Bezdedeanu’s teachings of the system receiving a rejection of the remediation to provide the ability for users to approve or disapprove potential remedial changes which bypasses the usual writing of data to persistent storage for potential remedial changes, such that the potential remedial changes do not automatically get committed to persistent storage at the next consistency point (column 6, lines 23-32 of Bezdedeanu).
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to FELICIA FARROW whose telephone number is (571)272-1856. The examiner can normally be reached M - F 7:30am-4:00pm (EST).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached at (571)270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/F.F/Examiner, Art Unit 2437
/ALI S ABYANEH/Primary Examiner, Art Unit 2437