Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
This non-final action is in response to RCE filed on 03/27/2026. In this RCE, claims 1-10, 12, 14-17 and 19-20 are amended. Claims 1-20 are pending, with claims 1, 8 and 15 being independent.
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 03/27/2026 has been entered.
Response to Arguments
Claim Objections
Objections are withdrawn in view of amended claims.
101 Rejections
Examiner would like to clarify that the Examiner indicated the proposed amendment would overcome 101 rejections in view of the proposed amendment discussed during interview (03/27/2026). However, the proposed amendment and claims filed on 03/27/2026 are not the same. Therefore, after reconsideration, 101 rejections are maintained for the claims filed on 03/27/2026.
Rejections are maintained because the new limitations regarding claim 1 are mental processes. For instance, the claim recites a system comprising: generate data identifying the detected network event and one or more additional detected network events, the one or more additional detected network events having occurred within a window of time that includes a time at which the detected network event occurred; identify, from among the detected network event and the one or more additional detected network events, correlated network events; and generate data indicating a logical order in which the correlated network events occurred. These are abstract idea including mental processes. For instance, a human can, in the human mind or on paper, generate/ create data that identifies the detected network event and one or more additional detected network events, the one or more additional detected network events having occurred within a window of time that includes a time at which the detected network event occurred. The human can, in the human mind or on paper, identify/ determine/ detect correlated network events from among the detected network event and the one or more additional detected network events. Moreover, the human can, in the human mind or on paper, generate/ create data/graph indicating an order in which the correlated network events occurred. Accordingly, the claim recites a judicial exception. This judicial exception is not integrated into a practical application. The claim also recites additional element at least one processor and a memory storing instructions that, when executed by the processor, cause the processor to and receive data corresponding to a detected network event and using a causation model that operates based at least in part on data identifying relationships among network entities in different network layers. The processor and the memory storing instructions are recited at a high-level of generality such that it amounts no more than mere instructions to apply the exception using a generic computer component, receiving step is mere obtaining data and a causation model can be a computer implemented machine learning model there is no improvement to the functioning of a computer nor to any other technology. At best, the claimed combination amounts to an improvement to the abstract idea of correlation events rather to any technology. Therefore, the additional elements are insignificant extra-solution activities. Accordingly, the additional elements do not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the processor and the memory storing instructions are recited at a high-level of generality such that it amounts no more than mere instructions to apply the exception using a generic computer component, receiving step is mere obtaining data and a causation model can be a computer implemented machine learning model there is no improvement to the functioning of a computer nor to any other technology. At best, the claimed combination amounts to an improvement to the abstract idea of correlation events rather to any technology. Therefore, these additional elements are insignificant extra-solution activities. Therefore, the claim is not patent eligible.
Section 102 and 103 Rejections
Applicant’s arguments with respect to claim(s) 1 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Claim Objections
Claim 17 is objected to because of “instructions are executable to generated a directed network” (emphasis added).
Appropriate correction is required.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
With respect to claim 1, the claim recites a system comprising: generate data identifying the detected network event and one or more additional detected network events, the one or more additional detected network events having occurred within a window of time that includes a time at which the detected network event occurred; identify, from among the detected network event and the one or more additional detected network events, correlated network events; and generate data indicating a logical order in which the correlated network events occurred. These are abstract idea including mental processes. For instance, a human can, in the human mind or on paper, generate/ create data that identifies the detected network event and one or more additional detected network events, the one or more additional detected network events having occurred within a window of time that includes a time at which the detected network event occurred. The human can, in the human mind or on paper, identify/ determine/ detect correlated network events from among the detected network event and the one or more additional detected network events. Moreover, the human can, in the human mind or on paper, generate/ create data/graph indicating an order in which the correlated network events occurred. Accordingly, the claim recites a judicial exception.
This judicial exception is not integrated into a practical application. The claim also recites additional element at least one processor and a memory storing instructions that, when executed by the processor, cause the processor to and receive data corresponding to a detected network event and using a causation model that operates based at least in part on data identifying relationships among network entities in different network layers. The processor and the memory storing instructions are recited at a high-level of generality such that it amounts no more than mere instructions to apply the exception using a generic computer component, receiving step is mere obtaining data and a causation model can be a computer implemented machine learning model there is no improvement to the functioning of a computer nor to any other technology. At best, the claimed combination amounts to an improvement to the abstract idea of correlation events rather to any technology. Therefore, the additional elements are insignificant extra-solution activities. Accordingly, the additional elements do not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea.
The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the processor and the memory storing instructions are recited at a high-level of generality such that it amounts no more than mere instructions to apply the exception using a generic computer component, receiving step is mere obtaining data and a causation model can be a computer implemented machine learning model there is no improvement to the functioning of a computer nor to any other technology. At best, the claimed combination amounts to an improvement to the abstract idea of correlation events rather to any technology. Therefore, these additional elements are insignificant extra-solution activities. Therefore, the claim is not patent eligible.
Claim 2 depends on claim 1, thus is having the same issue as shown above. Further, the claim also recites further configured to generate, based at least in part on the data indicating the logical order in which the correlated network events occurred, a data structure representing the correlated network events and encoding relationships among the correlated network events. This is an abstract idea including mental processes. For instance, a human can, in the human mind or on paper, generate/ draw a data structure representing the correlated network events and encoding relationships among the correlated network events. Therefore, these are abstract idea including mental processes. Accordingly, the claim recites a judicial exception.
This judicial exception is not integrated into a practical application. The claim also recites additional element that encodes relationships among the events identified by the system. This element mere provides explanation regarding the data structure, thus are insignificant extra-solution activities. Accordingly, the additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea.
The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element mere provides explanation regarding the data structure, thus are insignificant extra-solution activities, thus are insignificant extra-solution activities. Therefore, the claim is not patent eligible.
Claim 3 depends on claim 1, thus is having the same issue as shown above. Further, the claim also recites configured to modify the data indicating the logical order, responsive to receiving, from a user device, an input indicating at least one modification to relationships between one or more network events selected from the detected network event and the one or more additional detected network events, and one or more network entities. These elements clarify an abstract idea above, thus, are part of recitation of the abstract idea. Therefore, claim 3 also includes limitations are directed to an abstract idea without significantly more as discussed above.
Claim 4 depends on claim 1, thus is having the same issue as shown above. Further, the claim also recites the system is configured to store the data indicating the logical order in association with the detected network event in a data structure to facilitate automated root cause analysis. These elements clarify an abstract idea above, thus, are part of recitation of the abstract idea. Therefore, claim 4 also includes limitations are directed to an abstract idea without significantly more as discussed above.
Claim 5 depends on claim 1, thus is having the same issue as shown above. Further, the claim also recites the data identifying relationships among network entities in different network layers is determined based at least in part on a user configuration that defines a set of network entities. These elements clarify an abstract idea above, thus, are part of recitation of the abstract idea. Therefore, claim 5 also includes limitations are directed to an abstract idea without significantly more as discussed above.
Claim 6 depends on claim 1, thus is having the same issue as shown above. Further, the claim also recites generate a vector representation of each of the detected network event and the one or more additional detected network events, and compare the vector representations to identify the correlated network events. These are abstract idea including mental processes. For instance, a human can, in the human mind or on paper, generate/draw a vector representation of each of the detected network event and the one or more additional detected network events; and compare the vector representations to identify the correlated network events. Therefore, these are abstract idea including mental processes. Accordingly, the claim recites a judicial exception.
This judicial exception is not integrated into a practical application. The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. Therefore, the claim is not patent eligible.
The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. Therefore, the claim is not patent eligible.
Claim 7 depends on claim 1, thus is having the same issue as shown above. Further, the claim also recites the window of time is selected based at least in part on one or more attributes comprising a temporal proximity parameter, and wherein the logical order is determined independently of an order indicated by timestamps associated with the correlated network events. These elements clarify an abstract idea above, thus, are part of recitation of the abstract idea. Therefore, claim 7 also includes limitations are directed to an abstract idea without significantly more as discussed above.
With respect to claim 8, the claim recites computer implemented method comprising: generating, by the network management system, data identifying the detected network event and one or more additional detected network events, the one or more additional detected network events having occurred within a window of time that includes a time at which the detected network event occurred; identifying, from among the detected network event and the one or more additional detected network events, correlated network events; generating data indicating a logical order in which the correlated network events occurred. These are abstract idea including mental processes. For instance, a human can, in the human mind or on paper, generate/ create data that identifies the detected network event and one or more additional detected network events, the one or more additional detected network events having occurred within a window of time that includes a time at which the detected network event occurred. The human can, in the human mind or on paper, identify/ determine/ detect correlated network events from among the detected network event and the one or more additional detected network events. Moreover, the human can, in the human mind or on paper, generate/ create data/graph indicating an order in which the correlated network events occurred. Accordingly, the claim recites a judicial exception.
This judicial exception is not integrated into a practical application. The claim also recites additional element at least one processor and a memory storing instructions that, when executed by the processor, cause the processor to and receive data corresponding to a detected network event and using a causation model that operates based at least in part on data identifying relationships among network entities in different network layers. The processor and the memory storing instructions are recited at a high-level of generality such that it amounts no more than mere instructions to apply the exception using a generic computer component, receiving step is mere obtaining data and a causation model can be a computer implemented machine learning model there is no improvement to the functioning of a computer nor to any other technology. At best, the claimed combination amounts to an improvement to the abstract idea of correlation events rather to any technology. Therefore, the additional elements are insignificant extra-solution activities. Accordingly, the additional elements do not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea.
The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the processor and the memory storing instructions are recited at a high-level of generality such that it amounts no more than mere instructions to apply the exception using a generic computer component, receiving step is mere obtaining data and a causation model can be a computer implemented machine learning model there is no improvement to the functioning of a computer nor to any other technology. At best, the claimed combination amounts to an improvement to the abstract idea of correlation events rather to any technology. Therefore, these additional elements are insignificant extra-solution activities. Therefore, the claim is not patent eligible.
Claim 9 depends on claim 8, thus is having the same issue as shown above. Further, the claim also recites further comprising generating, by the network management system, based at least in part on the data indicating the logical order in which the correlated network events occurred, a data structure representing the correlated network events and encoding relationships among the correlated network events. This is an abstract idea including mental processes. For instance, a human can, in the human mind or on paper, generate/ draw a data structure representing the correlated network events and encoding relationships among the correlated network events. Therefore, these are abstract idea including mental processes. Accordingly, the claim recites a judicial exception.
This judicial exception is not integrated into a practical application. The claim also recites additional element that encodes relationships among the events identified by the system. This element mere provides explanation regarding the data structure, thus are insignificant extra-solution activities. Accordingly, the additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea.
The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element mere provides explanation regarding the data structure, thus are insignificant extra-solution activities, thus are insignificant extra-solution activities. Therefore, the claim is not patent eligible.
Claim 10 depends on claim 8, thus is having the same issue as shown above. Further, the claim also recites comprising modifying, by the network management system, the data indicating the logical order, responsive to receiving, from a user device, an input indicating at least one modification to relationships between one or more network events selected from the detected network event and the one or more additional detected network events, and one or more network entities These elements clarify an abstract idea above and are part of recitation of the abstract idea. Therefore, claim 10 also includes limitations are directed to an abstract idea without significantly more as discussed above.
Claim 11 depends on claim 8, thus is having the same issue as shown above. Further, the claim also recites one of the detected network event and the one or more additional detected network events is indicative of at least one network error corresponding to a computing network. These elements clarify an abstract idea above, thus, are part of recitation of the abstract idea. Therefore, claim 11 also includes limitations are directed to an abstract idea without significantly more as discussed above.
Claim 12 depends on claim 8, thus is having the same issue as shown above. Further, the claim also recites wherein the data identifying relationships among network entities in different network layers is determined based at least in part on a user configuration that defines a set of network entities. These elements clarify an abstract idea above, thus, are part of recitation of the abstract idea. Therefore, claim 12 also includes limitations are directed to an abstract idea without significantly more as discussed above.
Claim 13 depends on claim 8, thus is having the same issue as shown above. Further, the claim also recites generating, by the network management system, a vector representation of each of the detected network event and the one or more additional detected network events; and comparing, by the network management system, each vector representation with other vector representations to identify related network events. These are abstract idea including mental processes. For instance, a human can, in the human mind or on paper, generate/draw a vector representation of each of the detected network event and the one or more additional detected network events; and compare each vector representation with other vector representations to identify related network events. Therefore, these are abstract idea including mental processes. Accordingly, the claim recites a judicial exception.
This judicial exception is not integrated into a practical application. The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. Therefore, the claim is not patent eligible.
The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. Therefore, the claim is not patent eligible.
Claim 14 depends on claim 8, thus is having the same issue as shown above. Further, the claim also recites wherein the window of time is selected based at least in part on one or more attributes comprising a temporal proximity parameter, and wherein the logical order is identified irrespective of timestamps associated with the correlated network events. These elements clarify an abstract idea above, thus, are part of recitation of the abstract idea. Therefore, claim 14 also includes limitations are directed to an abstract idea without significantly more as discussed above.
With respect to claim 15, the claim recites generate data identifying the detected network event and one or more additional detected network events, the one or more additional detected network events having occurred within a window of time that includes a time at which the detected network event occurred; identify, from among the detected network event and the one or more additional detected network events, correlated network events; and generate data indicating a logical order in which the correlated network events occurred. These are abstract idea including mental processes. For instance, a human can, in the human mind or on paper, generate/ create data that identifies the detected network event and one or more additional detected network events, the one or more additional detected network events having occurred within a window of time that includes a time at which the detected network event occurred. The human can, in the human mind or on paper, identify/ determine/ detect correlated network events from among the detected network event and the one or more additional detected network events. Moreover, the human can, in the human mind or on paper, generate/ create data/graph indicating an order in which the correlated network events occurred. Accordingly, the claim recites a judicial exception.
This judicial exception is not integrated into a practical application. The claim also recites additional element at least one processor and a memory storing instructions that, when executed by the processor, cause the processor to and receive data corresponding to a detected network event and using a causation model that operates based at least in part on data identifying relationships among network entities in different network layers. The processor and the memory storing instructions are recited at a high-level of generality such that it amounts no more than mere instructions to apply the exception using a generic computer component, receiving step is mere obtaining data and a causation model can be a computer implemented machine learning model there is no improvement to the functioning of a computer nor to any other technology. At best, the claimed combination amounts to an improvement to the abstract idea of correlation events rather to any technology. Therefore, the additional elements are insignificant extra-solution activities. Accordingly, the additional elements do not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea.
The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the processor and the memory storing instructions are recited at a high-level of generality such that it amounts no more than mere instructions to apply the exception using a generic computer component, receiving step is mere obtaining data and a causation model can be a computer implemented machine learning model there is no improvement to the functioning of a computer nor to any other technology. At best, the claimed combination amounts to an improvement to the abstract idea of correlation events rather to any technology. Therefore, these additional elements are insignificant extra-solution activities. Therefore, the claim is not patent eligible.
Claim 16 depends on claim 15, thus is having the same issue as shown above. Further, the claim also recites wherein the logical order identifies at least one correlated network event as upstream of another correlated network event and is independent of an order indicated by timestamps associated with the correlated network events. These elements clarify an abstract idea above, thus, are part of recitation of the abstract idea. Therefore, claim 16 also includes limitations are directed to an abstract idea without significantly more as discussed above.
Claim 17 depends on claim 15, thus is having the same issue as shown above. Further, the claim also recites the instructions are executable to generated a directed network event graph that indicates a probabilistic root-cause network event and one or more related network events. These elements clarify an abstract idea above, thus, are part of recitation of the abstract idea. Therefore, claim 17 also includes limitations are directed to an abstract idea without significantly more as discussed above.
Claim 18 depends on claim 15, thus is having the same issue as shown above. Further, the claim also recites wherein one of the detected network event and the one or more additional detected network events is indicative of at least one network error corresponding to a computing network. These elements clarify an abstract idea above, thus, are part of recitation of the abstract idea. Therefore, claim 18 also includes limitations are directed to an abstract idea without significantly more as discussed above.
Claim 19 depends on claim 15, thus is having the same issue as shown above. Further, the claim also recites the instructions are executable to: generate vector representations of the detected network event and the one or more additional detected network events; and compare the vector representations to identify the correlated network events. These are abstract idea including mental processes. For instance, a human can, in the human mind or on paper, generate/draw a vector representation of each of the detected network event and the one or more additional detected network events; and compare the vector representations to identify the correlated network events. Therefore, these are abstract idea including mental processes. Accordingly, the claim recites a judicial exception.
This judicial exception is not integrated into a practical application. The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. Therefore, the claim is not patent eligible.
The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. Therefore, the claim is not patent eligible.
Claim 20 depends on claim 15, thus is having the same issue as shown above. Further, the claim also recites wherein the instructions are executable to generate a vector representation of each of the detected network event and the one or more additional detected network events. These are abstract idea including mental processes. For instance, a human can, in the human mind or on paper, generate/draw a vector representation of each of the detected network event and the one or more additional detected network events. Therefore, these are abstract idea including mental processes. Accordingly, the claim recites a judicial exception.
This judicial exception is not integrated into a practical application. The claim also recites additional element each vector representation encoding network-specific metadata associated with the respective network event is providing information regarding vector, thus are insignificant extra-solution activities. Accordingly, the additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea.
The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. The claim also recites additional element each vector representation encoding network-specific metadata associated with the respective network event is providing information regarding vector, thus are insignificant extra-solution activities, thus are insignificant extra-solution activities. Therefore, the claim is not patent eligible.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-2, 4, 8-9, 11, 14-15 and 17-18 are rejected under 35 U.S.C. 103 as being unpatentable over Muntes-Mulero et al. (US 2017 /0279660, Pub. Date: Sep. 28, 2017, hereinafter “Muntes”), in view of Wang et al. (US 2019/0165988, Pub. Date: May 30, 2019).
As per claim 1, Muntes discloses a system (Muntes fig.1 and para. [0019], FIG. 1 depicts an example system for generating and augmenting a context graph) comprising at least one processor and a memory storing instructions that, when executed by the processor (Muntes fig. 7 and para. [0098], The computer system includes a processor unit 701 (possibly including multiple processors, multiple cores, multiple nodes, and/or implementing multi-threading, etc.). The computer system includes memory 707), cause the processor to:
receive data corresponding to a detected network event (Muntes para. [0047], The generator may retrieve the event log by querying an event database; Muntes fig. 6 and para. [0079], The correlator begins operations for each anomalous event identified in the event log (606). The anomalous event for which the correlator is currently performing operations is hereinafter referred to as the "selected anomalous event."; Muntes para. [0078], An anomalous event is an event that indicates a network occurrence or condition that deviates from a normal or expected value or outcome); and
generate data identifying the detected network event and one or more additional detected network events (Muntes para. [0083], The correlator determines whether the probability exceeds a threshold y (612) [determining/generating probability]. The threshold y is a configured value that is set to a probability value, such as 0.4. The threshold value y may vary based on the types of events being correlated, types of components … If the probability does not exceed the threshold y, the correlator selects the next anomalous event (606), and no relationship between the first component and the second component is indicated; Muntes para. [0081], the correlator may search the anomalous events identified at process block 604 with an identifier for the component associated with the selected anomalous event ("the first component") [detected network event] and an identifier for the component corresponding to the other anomalous event ("the second component") one or more additional detected network events]), the one or more additional detected network events having occurred within a window of time that includes a time at which the detected network event occurred (Muntes fig. 6, block 608 and para. [0080], The correlator determines whether another anomalous event [one or more additional detected network events] occurred within a time window or period x within which the selected anomalous event [selected event] occurred (608) … If the correlator determines that another anomalous event did not occur within a time window x, the correlator selects the next anomalous event (606));
identify, from among the detected network event and the one or more additional detected network events, correlated network events (Muntes fig. 6 identifying corrected network events based on probability exceeds a threshold at block 612, 614 and 606; Muntes para. [0083-0084], The correlator determines whether the probability exceeds a threshold y (612). The threshold y is a configured value that is set to a probability value, such as 0.4. The threshold value y may vary based on the types of events being correlated, types of components … If the probability does not exceed the threshold y, the correlator selects the next anomalous event (606), and no relationship between the first component and the second component is indicated. If the probability that the anomalous event is related to the selected anomalous event does exceed the threshold y, the correlator generates nodes and edges corresponding to the first component and the second component); and
generate data (Muntes fig. 6, Generate Nodes And Edges Corresponding To The Components In The Anomalous Events at block 614) indicating a logical order in which the correlated network events occurred (Muntes para. [0072], The directionality of the edges may be based on a direction of causality between the components (i.e., an event at a first component caused an event at a second component; Muntes fig.1 and para. [0028], the directionality of the edges … may indicate component-based event dependencies such as a failure chain in which a failure in the component X 101 causes a failure in the component Y 102 and the component Z 103. [These citations show that the directionality of the edge indicates the order of the network events e.g., a failure in the component X 101 occurred first and then causes the failures in the component Y 102 and the component Z 103]).
Muntes teaches generating nodes and edges corresponding to the components in the anomalous events indicating a logical order in which the correlated network events occurred (Muntes fig. 6, para. 28, 72). Muntes does not explicitly disclose generating using a causation model that operates based at least in part on data identifying relationships among network entities in different network layers (i.e., generate, using a causation model that operates based at least in part on data identifying relationships among network entities in different network layers, data indicating a logical order in which the correlated network events occurred).
Wang teaches:
generate, using a causation model that operates based at least in part on data identifying relationships among network entities in different network layers, nodes and edges (Wang para. [0031], The causality modeler 125 generates an event model based on the received cross-layer network topology and the input of the received causality data 120 … the event model is a bi-partite causality graph. The bi-partite causality graph is a graph including nodes representing network failure events (e.g., a router failure or circuit failure-which may be root causes) and edges representing causality relationships between each and every network failure event in the network; Wang para. [0029], the topology collector 115 may fetch the network data from the network data sources 105 in order to generate the cross-layer network topology. In broad terms, the cross-layer network topology identifies the inter-connections that exist in or between the L1, L2, and L3 layers that are associated with all of the network entities identified in the network topology data for use in correlating the root causes of network failures in the entire network).
It would been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to modify Muntes in view of Wang in order to incorporate a causation model that operates based at least in part on data identifying relationships among network entities in different network layers to generate data indicating a logical order in which the correlated network events occurred.
One of ordinary skill in the art would have been motived because it offers the advantage of improve the accuracy and processing speed for determining correlated root causes that may be associated with observed network failure events (Wang para. [0023]).
As per claim 2, Muntes-Wang the system according to claim 1, as set forth above, Muntes also discloses wherein the system is further configured to generate, based at least in part on the data indicating the logical order in which the correlated network events occurred (Muntes fig. 6, Generate Nodes And Edges Corresponding To The Components In The Anomalous Events at 614), a data structure (Muntes fig. 5, Augment Context Graph With The Nodes And Edges at 512; Muntes para. [0077], The operations depicted in FIG. 6 are examples of operations that may be performed at process block 506 of FIG. 5) representing the correlated network events and encoding relationships among the correlated network events (Muntes [0031], the augmenter 112 augments the context graph 111 with additional edges or nodes to create an augmented context graph 113. The augmenter 112 adds nodes and edges that correspond to the additional component relationships indicated by the correlated events. In FIG. 1, the augmenter 112 adds an edge between the component Y 102 and the component Z 103 based on determining that an event at component Y 102 caused an event at component Z 103 at stage E).
As per claim 4, Muntes-Wang discloses the system according to claim 1, as set forth above, Muntes-Wang also discloses wherein the system is configured to store the data indicating the logical order in association with the detected network event in a data structure to facilitate automated root cause analysis (Muntes fig. 6, Generate Nodes And Edges Corresponding To The Components In The Anomalous Events at 614; Muntes [0031-0032], the augmenter 112 augments the context graph 111 with additional edges or nodes to create an augmented context graph 113. The augmenter 112 adds nodes and edges that correspond to the additional component relationships indicated by the correlated events… The analyzer 114 may use the augmented context graph 113 to perform root cause analysis).
Per claims 8-9, they do not teach or further define over the limitations in claims 1-2 respectively. As such, claims 8-9 are rejected for the same reasons as set forth in claims 1-2 respectively.
As per claim 11, Muntes-Wang discloses the system according to claim 8, as set forth above, Muntes also discloses wherein one of the detected network event and the one or more additional detected network events is indicative of at least one network error corresponding to a computing network (Muntes fig. 6 and para. [0080], The correlator determines whether another anomalous event occurred within a time window or period x within which the selected anomalous event occurred (608); Muntes para. [0078], An anomalous event is an event that indicates a network occurrence or condition that deviates from a normal or expected value or outcome).
As per claim 14, Muntes-Wang discloses the method according to claim 8, as set forth above, Muntes also discloses wherein the window of time is selected based at least in part on one or more attributes comprising a temporal proximity parameter (Muntes para. [0080], The correlator determines whether another anomalous event occurred within a time window or period x within which the selected anomalous event occurred (608). The time window x is a configurable value that instructs the correlator how far back in time to search for another anomalous event … The length of the time window x may be based on a statistical determination that if two events did not occur within a certain temporal proximity then they are unlikely to be related. The time window x may be adjusted based on the results of correlation analysis), and wherein the logical order is identified irrespective of timestamps associated with the correlated network events (Muntes para. [0028], The nodes of the context graph 111 represent the components in the network 104 while the edges of the graph represent structural and/or operational relationships between the components … the directionality of the edges may not indicate inter-component dependencies but may instead indicate a flow of data or may indicate component-based event dependencies such as a failure chain in which a failure in the component X 101 causes a failure in the component Y 102 and the component Z 103).
Per claims 15 and 18, they do not teach or further define over the limitations in claims 8 and 11 respectively. As such, claims 15-16 and 18 are rejected for the same reasons as set forth in claims 8-9 and 11 respectively.
As per claim 17, Muntes-Wang discloses the non-transitory computer-readable medium according to claim 15, as set forth above, Muntes also discloses wherein the instructions are executable to generated a directed network event graph that indicates a probabilistic root-cause network event and one or more related network events
Wang teaches:
the instructions are executable to generated a directed network event graph that indicates a probabilistic root-cause network event and one or more related network events (Wang para. [0031], The causality modeler 125 generates an event model based on the received cross-layer network topology and the input of the received causality data 120 … the event model is a bi-partite causality graph. The bi-partite causality graph is a graph including nodes representing network failure events (e.g., a router failure or circuit failure-which may be root causes) and edges representing causality relationships between each and every network failure event in the network; Wang para. [0062], The correlator 140 may maintain the structure of network entities and connection represented in the event model and may assign a prior probability, represented for example as Pr(root cause), to each root cause node in the event mode)
It would been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to further modify Muntes in view of Wang generating a directed network event graph that indicates a probabilistic root-cause network event and one or more related network events.
One of ordinary skill in the art would have been motived because it offers the advantage of improve the accuracy and processing speed for determining correlated root causes that may be associated with observed network failure events (Wang para. [0023]).
Claims 3 and 10 are rejected under 35 U.S.C. 103 as being unpatentable over Muntes-Mulero et al. (US 2017 /0279660, Pub. Date: Sep. 28, 2017, hereinafter “Muntes”), in view of Wang et al. (US 2019/0165988, Pub. Date: May 30, 2019), in view of Feinstein et al. (US 9,049,105, Date of Patent: Jun. 2, 2015).
As per claim 3, Muntes-Wang discloses the system according to claim 1, as set forth above, Muntes also discloses wherein the system is configured to modify the data indicating the logical order (Muntes para. [0058], existing nodes and edges may be removed from the context graph; Muntes para. [0072], The directionality of the edges may be based on a direction of causality between the components (i.e., an event at a first component caused an event at a second component), responsive to receiving, from event rule, indicating at least one modification to relationships between one or more network events selected from the detected network event and the one or more additional detected network events, and one or more network entities (Muntes para. [0058], existing nodes and edges may be removed from the context graph. For example, an event rule may indicate that an edge should be removed if no event indication corresponding to the relationship indicated by the edge has been received for a period of time. Or, for example, an edge may be removed if an attribute value in an additional event indication, such as a number of invocations, falls below a relationship indication threshold).
Muntes does not explicitly disclose:
modify the data, responsive to receiving, from a user device, an input indicating at least one modification to relationships.
Feinstein teaches:
modify the data (Feinstein col. 16 lines 61-67, new dependency information may cause certain events to be split from or extracted from event sequences because they may be more related to a different incident than determined by previous rules, in one embodiment; Feinstein col. 19 lines 6-8, the computing device may monitor event records in event sequences associated with certain incidents and/or network elements; Feinstein col. 2 lines 15-16, Such multiple event records may be stored in an event sequence associated with the incident), responsive to receiving, from a user device (Feinstein fig. 1, user device 104), an input indicating at least one modification to relationships (Feinstein col. 16 lines 21-25, The rules may affect the storage of event records in real-time (e.g., as the event records are created and stored initially) or after event records are initially stored according to a user's manual direction to, for example, resort event records in event sequences based on new or updated rules and/or dependencies).
It would been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to further modify Muntes in view of Feinstein in order to incorporate user input to modify relationships between one or more network events selected from the detected network event and the one or more additional detected network events, and one or more network entities.
One of ordinary skill in the art would have been motived because it offers the advantage of providing ability for user to adjust or correct relationship between events.
Per claim 10, it does not teach or further define over the limitations in claim 3. As such, claim 10 is rejected for the same reasons as set forth in claim 3.
Claims 5 and 12 are rejected under 35 U.S.C. 103 as being unpatentable over Muntes-Mulero et al. (US 2017/0279660, Pub. Date: Sep. 28, 2017, hereinafter “Muntes”), in view of Wang et al. (US 2019/0165988, Pub. Date: May 30, 2019), Brandwine et al. (US 9,276,811, Date of Patent: Mar. 1, 2016).
As per claim 5, Muntes-Wang discloses the system according to claim 1, as set forth above, Muntes does not explicitly disclose wherein the data identifying relationships among network entities in different network layers is determined based at least in part on a user configuration that defines a set of network entities.
Wang teaches:
data identifying relationships among network entities in different network layers is determined (Wang para. [0031], The causality modeler 125 generates an event model based on the received cross-layer network topology and the input of the received causality data 120 … the event model is a bi-partite causality graph. The bi-partite causality graph is a graph including nodes representing network failure events (e.g., a router failure or circuit failure-which may be root causes) and edges representing causality relationships between each and every network failure event in the network; Wang para. [0029], the topology collector 115 may fetch the network data from the network data sources 105 in order to generate the cross-layer network topology. In broad terms, the cross-layer network topology identifies the inter-connections that exist in or between the L1, L2, and L3 layers that are associated with all of the network entities identified in the network topology data for use in correlating the root causes of network failures in the entire network) based at least in part on configuration that defines a set of network entities (Wang para. [0026], the network topology data may identify data for and mappings between pairs of network entities that are related to layers of the open systems interconnection (OSI) model such as the physical layer (e.g., L1), the data link layer (e.g., L2), and/or the network layer (e.g., L3); Wang para. [0029], The network topology can change frequently as network entities are added or removed from the network).
It would been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to further modify Muntes in view of Wang for the data identifying relationships among network entities in different network layers is determined based at least in part on a configuration that defines a set of network entities.
One of ordinary skill in the art would have been motived because it offers the advantage of improve the accuracy and processing speed for determining correlated root causes that may be associated with observed network failure events (Wang para. [0023]).
Wang teaches a configuration (i.e., changing frequently as network entities are added or removed from the network) that defines a set of network entities (Wang para. 26, 29). However, Wang does not explicitly disclose a configuration is a user configuration (i.e., a user configuration that defines a set of network entities).
Brandwine teaches:
a user configuration that defines a set of network entities (Brandwine col. 55 lines 36-39, receiving, from a user, configuration information that specifies a network topology for the first virtual computer network including multiple virtual router devices).
It would been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to further modify Muntes in view of Brandwine in order to incorporate a user configuration that defines a set of network entities for determining data identifying relationships among network entities in different network layers.
One of ordinary skill in the art would have been motived because it offers the advantage of providing ability for user to adjust or correct relationship between events.
Per claim 12, it does not teach or further define over the limitations in claim 5. As such, claim 12 is rejected for the same reasons as set forth in claim 5.
Claims 6, 13 and 19-20 are rejected under 35 U.S.C. 103 as being unpatentable over Muntes-Mulero et al. (US 2017/0279660, Pub. Date: Sep. 28, 2017, hereinafter “Muntes”), in view of Wang et al. (US 2019/0165988, Pub. Date: May 30, 2019), in view of Wilkinson (US 2013/0163438, Pub. Date: US 2013/0163438).
As per claim 6, Muntes-Wang discloses the system according to claim 1, as set forth above, Muntes does not explicitly disclose wherein the system is configured to generate a vector representation of each of the detected network event and the one or more additional detected network events, and compare the vector representations to identify the correlated network events.
Wilkinson teaches:
generate a vector representation of each of the detected network event and the one or more additional detected network events (Wilkinson fig. 4 and para. [0057], At block 405, monitoring system 100 may receive a first set of vectors (e.g., Aevents), each vector representing a network event generated by a telecommunications network testing system (e.g., device 105). At block 410, monitoring system 100 may receive a second set of vectors (e.g., Mevent), each vector representing a network event as observed by monitoring system 100), and compare the vector representations to identify the correlated network events (Wilkinson fig. 4 and para. [0058], At block 415, monitoring system 100 may identify corresponding or matching [comparing] vectors among the first and second set that represent corresponding or matching network events).
It would been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to further modify Muntes in view of Wilkinson for generating a vector representation of each of the detected network event and the one or more additional detected network events, and comparing the vector representations to identify the correlated network events.
One of ordinary skill in the art would have been motived because it offers the advantage of identifying correlation among network events.
As per claim 13, Muntes-Wang discloses the method according to claim 8, as set forth above, Muntes does not explicitly disclose, further comprising:
generating, by the network management system, a vector representation of each of the detected network event and the one or more additional detected network events; and
comparing, by the network management system, each vector representation with other vector representations to identify related network events.
Wilkinson teaches:
generating, by the network management system, a vector representation of each of the detected network event and the one or more additional detected network events (Wilkinson fig. 4 and para. [0057], At block 405, monitoring system 100 may receive a first set of vectors (e.g., Aevents), each vector representing a network event generated by a telecommunications network testing system (e.g., device 105). At block 410, monitoring system 100 may receive a second set of vectors (e.g., Mevent), each vector representing a network event as observed by monitoring system 100); and
comparing, by the network management system, each vector representation with other vector representations to identify related network events (Wilkinson fig. 4 and para. [0058], At block 415, monitoring system 100 may identify corresponding or matching [comparing] vectors among the first and second set that represent corresponding or matching network events).
It would been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to further modify Muntes in view of Wilkinson for generating, by the network management system, a vector representation of each of the detected network event and the one or more additional detected network events; and comparing, by the network management system, each vector representation with other vector representations to identify related network events.
One of ordinary skill in the art would have been motived because it offers the advantage of identifying correlation among network events.
Per claim 19, it does not teach or further define over the limitations in claim 6. As such, claim 19 is rejected for the same reasons as set forth in claim 6.
As per claim 20, Muntes-Wang discloses the non-transitory computer-readable medium according to claim 15, as set forth above, Muntes does not explicitly disclose wherein the instructions are executable to generate a vector representation of each of the detected network event and the one or more additional detected network events, each vector representation encoding network-specific metadata associated with the respective network event.
Wilkinson teaches:
generate a vector representation of each of the detected network event and the one or more additional detected network events (Wilkinson fig. 4 and para. [0057], At block 405, monitoring system 100 may receive a first set of vectors (e.g., Aevents), each vector representing a network event generated by a telecommunications network testing system (e.g., device 105). At block 410, monitoring system 100 may receive a second set of vectors (e.g., Mevent), each vector representing a network event as observed by monitoring system 100), each vector representation encoding network-specific metadata associated with the respective network event (Wilkinson fig. 4 and para. [0057], At block 405, monitoring system 100 may receive a first set of vectors (e.g., Aevents), each vector representing a network event generated by a telecommunications network testing system (e.g., device 105; Wilkinson para. [0007-0008], each vector in the first set of vectors including a plurality of dimension … the values associated with the plurality of dimensions may include at least one of: session length, uplink byte count, downlink byte count, number of attempts, number of failures, or latency).
It would been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to further modify Muntes in view of Wilkinson for generating a vector representation of each of the detected network event and the one or more additional detected network events, each vector representation encoding network-specific metadata associated with the respective network event.
One of ordinary skill in the art would have been motived because it offers the advantage of identifying correlation among network events.
Claims 7 and 16 rejected under 35 U.S.C. 103 as being unpatentable over Muntes-Mulero et al. (US 2017/0279660, Pub. Date: Sep. 28, 2017, hereinafter “Muntes”), in view of Wang et al. (US 2019/0165988, Pub. Date: May 30, 2019), in view of dos Santos et al. (US 2021/0203673, Pub. Date: Jul. 1, 2021, hereinafter “Santos”).
As per claim 7, Muntes-Wang discloses the system according to claim 1, as set forth above, Muntes also discloses wherein the window of time is selected based at least in part on one or more attributes comprising a temporal proximity parameter (Muntes para. [0080], The correlator determines whether another anomalous event occurred within a time window or period x within which the selected anomalous event occurred (608). The time window x is a configurable value that instructs the correlator how far back in time to search for another anomalous event … The length of the time window x may be based on a statistical determination that if two events did not occur within a certain temporal proximity then they are unlikely to be related. The time window x may be adjusted based on the results of correlation analysis).
Muntes does not explicitly disclose:
wherein the logical order is determined independently of an order indicated by timestamps associated with the correlated network events.
Santos teaches:
logical order is determined independently of an order indicated by timestamps associated with the correlated network events (Santos fig. 12 and para. [0145], an algorithm for determining an event chain can incorporate attributes including event type, timestamp at which the events or alerts were raised, severity of alerts, source IP address and destination IP address in order to correlate them to determine the chained events (e.g., issues); Santos para. [0142], The type of chaining can depend on the event (e.g., alert) timestamp ordering. A forward chain may be determined based on accessing events from a database, ordering the events by timestamps from past to present, and then applying an algorithm to determine the event chains).
It would been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to further modify Muntes in view of Santos for logical order is determined independently of an order indicated by timestamps associated with the correlated network events.
One of ordinary skill in the art would have been motived because it offers the advantage of improving investigation of issues (see Santos para. [0070]).
As per claim 16, Muntes-Wang discloses the non-transitory computer-readable medium according to claim 15, as set forth above, Muntes also discloses wherein the logical order identifies at least one correlated network event as upstream of another correlated network event (Muntes fig. 6, Generate Nodes And Edges Corresponding To The Components In The Anomalous Events at block 614 and para. [0072], The directionality of the edges may be based on a direction of causality between the components (i.e., an event at a first component caused an event at a second component; Muntes fig.1 and para. [0028], the directionality of the edges … may indicate component-based event dependencies such as a failure chain in which a failure in the component X 101 causes a failure in the component Y 102 and the component Z 103; Muntes para. [0030], the event analyzer 107 analyzes events to identify direct component relationships, such as the component X 101 invokes the component Y 102. The event correlator 116, however, identifies component relationships based on correlating two or more events. Correlations may arise from a cause-and-effect type relationship. For example, in FIG. 1, the event correlator 116 may identify a relationship between the component Y 102 and the component Z 103 based on an event at the component Y 102 [correlated network event], such as a high processor load event, which caused an event at the component Z 103 [another correlated network event], such as a low memory event).
Muntes does not explicitly disclose:
the logical order is independent of an order indicated by timestamps associated with the correlated network events.
Santos teaches:
logical order is independent of an order indicated by timestamps associated with the correlated network events (Santos fig. 12 and para. [0145], an algorithm for determining an event chain can incorporate attributes including event type, timestamp at which the events or alerts were raised, severity of alerts, source IP address and destination IP address in order to correlate them to determine the chained events (e.g., issues); Santos para. [0142], The type of chaining can depend on the event (e.g., alert) timestamp ordering. A forward chain may be determined based on accessing events from a database, ordering the events by timestamps from past to present, and then applying an algorithm to determine the event chains).
It would been obvious to one of ordinary skill in the art before the effective filling date of the claimed invention to further modify Muntes in view of Santos for the logical order is independent of an order indicated by timestamps associated with the correlated network events.
One of ordinary skill in the art would have been motived because it offers the advantage of improving investigation of issues (see Santos para. [0070]).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Matsuo et al. (US 20230208723) Model Construction Apparatus, Estimation Apparatus, Model Construction Method, Estimation Method And Program;
Ma et al. (US 20230247459) Physical Layer Cross-Link Interference Measurement And Reporting;
Chen et al. (US 20230112534) Artificial Intelligence Planning Method And Real-Time Radio Access Network Intelligence Controller.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to VINH NGUYEN whose telephone number is (571)272-4487. The examiner can normally be reached Monday-Friday: 7:30 AM - 5:30 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, KAMAL B DIVECHA can be reached at (571)272-5863. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/VINH NGUYEN/Examiner, Art Unit 2453
/KAMAL B DIVECHA/Supervisory Patent Examiner, Art Unit 2453