Prosecution Insights
Last updated: August 18, 2026
Application No. 18/611,453

MICRO-SEGMENTATION WITHOUT INTERMEDIATE FIREWALL USING EBPF

Non-Final OA §101§103
Filed
Mar 20, 2024
Examiner
ABSHER, LUCAS DONALD
Art Unit
Tech Center
Assignee
Cisco Technology Inc.
OA Round
1 (Non-Final)
Grant Probability
Favorable
1-2
OA Rounds

Office Action

§101 §103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claim are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. 1. A method comprising: a. identifying one or more processes operating on a host network; b. assigning, a process identity to each of the one or more processes operating on the host network; c. monitoring, interactions between each of the one or more processes operating on the host network; d. identifying, a source and a destination of the interactions between each of the one or more processes operating on the host network; e. determining, a first process of the one or more processes operating on the host network does not interact with a second process of the one or more processes operating on the host network based on the source and the destination of the first process and the source and the destination of the second process; f. and blocking, interactions between the first process and the second process on the host network. g. by the host network h. by an extended Berkeley Packet Filter (eBPF) Claim 1 Step 1: Claim 1 is directed to a method identifying one or more processes operating on a host network, the method comprising: a series of steps, and is therefore directed to a process, which is one of the four statutory categories. Claim 1 Step 2A, Prong One: Limitations 1 a-e can be performed in the human mind through observation, evaluation, judgement and opinion, with the aid of pen and paper, and is/are therefore reciting a mental process. Accordingly, claim 1 recites a judicial exception (i.e., an abstract idea). Claim 1 Step 2A, Prong Two: Limitations 1 g,h provide mere instructions to implement the limitations which can be performed in the human mind, i.e., the judicial exception, on a computer, which is not indicative of integration into a practical application. See MPEP 2106.04(d) and 2106.0S(f). Limitation 1 f amounts to insignificant extra-solution activity of necessary data outputting, as it is merely outputting the result of the judicial exception, which is not indicative of integration into a practical application. See MPEP 2106.04(d) and 2106.0S(g). Claim 1Step 2B: The combination of these additional elements amounts to a method comprising steps which can be performed mentally implemented by generic computing components, and comprising a step of insignificant extra-solution and well-understood, routine and conventional activity. Therefore, the additional elements, when considered individually and in combination, fail to add an inventive concept to the claim. Consequently, claim 1 as a whole does not amount to significantly more than the recited judicial exceptions and the claim is not eligible. 2. The method of claim 1, further comprising: a. determining, a third process of the one or more processes operating on the host network interacts with the second process based on a source and a destination of the third process; b. and injecting, a security control between the second process and the third process. c. by the eBPF Claim 2 is dependent on claim 1, and therefore inherits the same judicial exception. Limitation 2 a recites steps that can performed in the human mind through observation, evaluation, judgement and opinion, with the aid of pen and paper, and is therefore reciting a mental process. In addition, the mention of the steps being performed on a computer in limitation 2 c, amounts to mere instructions to apply the exception for the same reasons presented with respect to claim 1. Furthermore, limitation 2 b amounts to mere data gathering and outputting, and is therefore insignificant extra-solution activity. This additional element of insignificant extra-solution activity is not indicative of integration into a practical application. Even when considered in combination with the additional elements of claim 1, the additional elements comprise mere instructions to apply the exception and insignificant extra-solution activity, which are not indicative of integration into a practical application. Thus, claim 2 is not eligible. 3. The method of claim 1, further comprising: a. identifying, a query from the first process to the second process; determining, by the eBPF, the query from the first process to the second process is an attack based on the blocking of interactions between the first process and the second process; b. and blocking, the query from the first process from interacting with the second process. c. by the eBPF d. by the host network Claim 3 is dependent on claim 1, and therefore inherits the same judicial exception. Limitation 3 a recites steps that can performed in the human mind through observation, evaluation, judgement and opinion, with the aid of pen and paper, and is therefore reciting a mental process. In addition, the mention of the steps being performed on a computer in limitations 3 c,d, amounts to mere instructions to apply the exception for the same reasons presented with respect to claim 1. Furthermore, limitation 3 b amounts to mere data gathering and outputting, and is therefore insignificant extra-solution activity. This additional element of insignificant extra-solution activity is not indicative of integration into a practical application. Even when considered in combination with the additional elements of claim 1, the additional elements comprise mere instructions to apply the exception and insignificant extra-solution activity, which are not indicative of integration into a practical application. Thus, claim 3 is not eligible. 4. The method of claim 3, further comprising: a. identifying, an IP five-tuple of the query; b. and blocking the IP five-tuple from further interacting with the host network. c. by the host network, Claim 4 is dependent on claim 3, and therefore inherits the same judicial exception. Limitation 4 a recites steps that can performed in the human mind through observation, evaluation, judgement and opinion, with the aid of pen and paper, and is therefore reciting a mental process. In addition, the mention of the steps being performed on a computer in limitation 4 c, amounts to mere instructions to apply the exception for the same reasons presented with respect to claim 1. Furthermore, limitation 4 b amounts to mere data gathering and outputting, and is therefore insignificant extra-solution activity. This additional element of insignificant extra-solution activity is not indicative of integration into a practical application. Even when considered in combination with the additional elements of claim 1, the additional elements comprise mere instructions to apply the exception and insignificant extra-solution activity, which are not indicative of integration into a practical application. Thus, claim 4 is not eligible. 5. The method of claim 3, a. wherein the query includes an encrypted data packet. Claim 5 is dependent on claim 3, and therefore inherits the same judicial exception. An integration into a practical application is not substantiated from the above. Thus, the claim is not eligible. 6. The method of claim 1, a. wherein the host network is a single server. Claim 6 is dependent on claim 1, and therefore inherits the same judicial exception. An integration into a practical application is not substantiated from the above. Thus, the claim is not eligible. 7. The method of claim 1, a. wherein the host network is a virtual local area network (VLAN). Claim 7 is dependent on claim 1, and therefore inherits the same judicial exception. An integration into a practical application is not substantiated from the above. Thus, the claim is not eligible. 8. A system comprising: a. a storage configured to store instructions; and a processor configured to execute the instructions and cause the processor to: b. identify one or more processes operating on a host network; c. assign, a process identity to each of the one or more processes operating on the host network; d. monitor interactions between each of the one or more processes operating on the host network; e. identify, a source and a destination of the interactions between each of the one or more processes operating on the host network; f. determine, a first process of the one or more processes operating on the host network does not interact with a second process of the one or more processes operating on the host network based on the source and the destination of the first process and the source and the destination of the second process; g. and block, interactions between the first process and the second process on the host network. h. by the host network i. by an extended Berkeley Packet Filter (eBPF) Limitations 8 b-i correspond to the limitations claim 1, and therefore inherit the same judicial exception. Limitation 8 a provides mere instructions to implement the limitations which can be performed in the human mind, i.e., the judicial exception, on a computer, which is not indicative of integration into a practical application. This additional element of insignificant extra-solution activity is not indicative of integration into a practical application. Even when considered in combination with the additional elements of claim 1, the additional elements comprise mere instructions to apply the exception, which is not indicative of integration into a practical application. Thus, claim 8 is not eligible. 9. The system of claim 8, further comprising: a. determining, a third process of the one or more processes operating on the host network interacts with the second process based on a source and a destination of the third process; b. and injecting, a security control between the second process and the third process. c. by the eBPF The above limitation(s) correspond to the limitations of claim 2, and therefore inherit the same judicial exception. 10. The system of claim 8, further comprising: a. identifying, a query from the first process to the second process; determining, by the eBPF, the query from the first process to the second process is an attack based on the blocking of interactions between the first process and the second process; b. and blocking, the query from the first process from interacting with the second process. c. by the eBPF d. by the host network The above limitation(s) correspond to the limitations of claim 3, and therefore inherit the same judicial exception. 11. The system of claim 10, further comprising: a. identifying, an IP five-tuple of the query; and blocking the IP five-tuple from further interacting with the host network. b. by the host network The above limitation(s) correspond to the limitations of claim 4, and therefore inherit the same judicial exception. 12. The system of claim 10, a. wherein the query includes an encrypted data packet. The above limitation(s) correspond to the limitations of claim 5, and therefore inherit the same judicial exception. 13. The system of claim 8, a. wherein the host network is a single server. The above limitation(s) correspond to the limitations of claim 6, and therefore inherit the same judicial exception. 14. The system of claim 8, a. wherein the host network is a virtual local area network (VLAN). The above limitation(s) correspond to the limitations of claim 7, and therefore inherit the same judicial exception. 15. A non-transitory computer readable medium comprising instructions, the instructions, when executed by a computing system, cause the computing system to: identify one or more processes operating on a host network; assign, by the host network, a process identity to each of the one or more processes operating on the host network; monitor, by an extended Berkeley Packet Filter (eBPF), interactions between each of the one or more processes operating on the host network; identify, by the eBPF, a source and a destination of the interactions between each of the one or more processes operating on the host network; determine, by the eBPF, a first process of the one or more processes operating on the host network does not interact with a second process of the one or more processes operating on the host network based on the source and the destination of the first process and the source and the destination of the second process; and block, by the eBPF, interactions between the first process and the second process on the host network. The above limitation(s) correspond to the limitations of claim 1, and therefore inherit the same judicial exception. 16. The non-transitory computer readable medium of claim 15, further comprising: a. determining, by the eBPF, a third process of the one or more processes operating on the host network interacts with the second process based on a source and a destination of the third process; b. and injecting, by the eBPF, a security control between the second process and the third process. The above limitation(s) correspond to the limitations of claim 2, and therefore inherit the same judicial exception. 17. The non-transitory computer readable medium of claim 15, further comprising: a. identifying, by the eBPF, a query from the first process to the second process; determining, by the eBPF, the query from the first process to the second process is an attack based on the blocking of interactions between the first process and the second process; b. and blocking, by the host network, the query from the first process from interacting with the second process. The above limitation(s) correspond to the limitations of claim 3, and therefore inherit the same judicial exception. 18. The non-transitory computer readable medium of claim 17, further comprising: a. identifying, by the host network, an IP five-tuple of the query; and blocking the IP five-tuple from further interacting with the host network. The above limitation(s) correspond to the limitations claim 4, and therefore inherit the same judicial exception. 19. The non-transitory computer readable medium of claim 15, a. wherein the host network is a single server. The above limitation(s) correspond to the limitations of claim 6, and therefore inherit the same judicial exception. 20. The non-transitory computer readable medium of claim 15, a. wherein the host network is a virtual local area network (VLAN). The above limitation(s) correspond to the limitations of claim 7, and therefore inherit the same judicial exception. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1,2,3,5,8,9,10,12,13,15,16,17,19 is/are rejected under 35 U.S.C. 103 as being unpatentable over 20240430680 A1, MOBILE NETWORK INFORMATION SHARING VIA EBPF FOR ZERO TRUST SECURITY, Rappard et. all, 2023-06-23 (Rappard hereafter) in view of 20190028496 A1, ANOMALY DETECTION FOR MICRO-SERVICE COMMUNICATIONS, Fenoglio et. all, 2022-07-31 (Fenoglio hereafter) as well as in further view of US 20240039959 A1, COMPLIANT DATA TRANSFERS, Yannuzzi et. all, 2022-07-31 (Yannuzzi hereafter). Rappard teaches the following substantially as claimed. 1. A method comprising: a. identifying one or more processes operating on a host network; [0028] In some embodiments, a system, process, and/or computer program product for providing mobile network information sharing via eBPF for zero trust security includes monitoring network traffic in a core mobile network using an agent executed on a network element in the core mobile network to identify a session associated with a User Equipment (UE) that attached to the core mobile network for mobile network communications; extracting meta information associated with the session using the agent executed on a network element in the core mobile network; sending the extracted meta information to a security platform located outside of the core mobile network; and enforcing a security policy on the session at the security platform based on the extracted meta information to apply granular-based security in the core mobile network based on a security policy. b. assigning, by the host network, a process identity to each of the one or more processes operating on the host network; [0028] In some embodiments, a system, process, and/or computer program product for providing mobile network information sharing via eBPF for zero trust security includes monitoring network traffic in a core mobile network using an agent executed on a network element in the core mobile network to identify a session associated with a User Equipment (UE) that attached to the core mobile network for mobile network communications; extracting meta information associated with the session using the agent executed on a network element in the core mobile network; sending the extracted meta information to a security platform located outside of the core mobile network; and enforcing a security policy on the session at the security platform based on the extracted meta information to apply granular-based security in the core mobile network based on a security policy. [0025] Specifically, in mobile networks, such as 5G service provider mobile networks or other 5G mobile networks, a portion of the communications over these mobile networks is often encrypted or on interfaces that are not open for inspection (e.g., security inspection using a security platform, such as an NGFW or another implementation of a security platform, such as a security sensor, for performing security inspection on mobile network traffic). Even if a security platform can access/decrypt such mobile network traffic and/or interfaces for security inspection on such a mobile network, it is often not an option to have a security platform located within, for example, the service provider mobile network to perform such security inspection. As a result, enforcement of granular security is inhibited as the security platform does not have access to key meta data associated with the mobile network traffic (e.g., meta data for sessions to facilitate granular security policy enforcement can include subscriber ID (e.g., International Mobile Subscriber Identity (IMSI) in a 4G mobile network and/or using Subscription Permanent Identifier (SUPI) in a 5G mobile network), equipment ID (e.g., International Mobile Equipment Identity (IMEI) in a 4G mobile network and/or using Permanent Equipment Identifier (PEI) in a 5G mobile network), network slice, and/or other meta data associated with the mobile network traffic), which also renders zero trust security difficult if not impossible for such mobile network environments. c. monitoring, by an extended Berkeley Packet Filter (eBPF), interactions between each of the one or more processes operating on the host network; [0060] FIG. 2E illustrates a logical flow for using an eBPF sensor deployed in a 5G core mobile network element to extract meta data from monitored user plane traffic in accordance with some embodiments. As shown in FIG. 2E, at 252, a User Equipment (UE) attaches or detaches to the 5G mobile network, or updates its state (e.g., from idle to active). At 254, various signaling messages are sent within the 5G core mobile network during the attach operation. At 256, the eBPF sensor (e.g., eBPF client/sensor, such as shown at 124A and 124B in FIG. 1) process is running by one or more hosts (e.g., network elements, such as executed on AMF 114 and/or SMF 116 as shown in FIG. 1), and the eBPF sensor detects key signaling messages. At 258, various meta data (e.g., key meta, such as one or more of the example meta data that the eBPF client can extract as shown at 260 in FIG. 2E), such as Equipment Identifiers (IDs) (e.g., IMEI/PEI), Subscriber Identifiers (IDs) (e.g., IMSI/SUPI), DNN, Tracking Area Information (TAI) and/or User Location Information (ULI), and the IP address(es) that they map to are sent from the eBPF sensor to the security platform (e.g., security sensor/NFGW) for performing security policy enforcement (e.g., granular and/or zero trust security policy enforcement), such as similarly described above. The UE in this context indicates the source, while the Data Network Name (DNN) identifies the destination. d. identifying, by the eBPF, a source and a destination of the interactions between each of the one or more processes operating on the host network; [0060] FIG. 2E illustrates a logical flow for using an eBPF sensor deployed in a 5G core mobile network element to extract meta data from monitored user plane traffic in accordance with some embodiments. As shown in FIG. 2E, at 252, a User Equipment (UE) attaches or detaches to the 5G mobile network, or updates its state (e.g., from idle to active). At 254, various signaling messages are sent within the 5G core mobile network during the attach operation. At 256, the eBPF sensor (e.g., eBPF client/sensor, such as shown at 124A and 124B in FIG. 1) process is running by one or more hosts (e.g., network elements, such as executed on AMF 114 and/or SMF 116 as shown in FIG. 1), and the eBPF sensor detects key signaling messages. At 258, various meta data (e.g., key meta, such as one or more of the example meta data that the eBPF client can extract as shown at 260 in FIG. 2E), such as Equipment Identifiers (IDs) (e.g., IMEI/PEI), Subscriber Identifiers (IDs) (e.g., IMSI/SUPI), DNN, Tracking Area Information (TAI) and/or User Location Information (ULI), and the IP address(es) that they map to are sent from the eBPF sensor to the security platform (e.g., security sensor/NFGW) for performing security policy enforcement (e.g., granular and/or zero trust security policy enforcement), such as similarly described above. The UE in this context indicates the source, while the Data Network Name (DNN) identifies the destination. Rappard does not explicitly teach the following limitation. e. determining, by the eBPF, a first process of the one or more processes operating on the host network does not interact with a second process of the one or more processes operating on the host network based on the source and the destination of the first process and the source and the destination of the second process; Fenoglio does however, [0033] FIG. 3A is a schematic diagram illustrating the format/arrangement of a micro-service communication record 360 in accordance with certain examples presented herein. In this example, the micro-service communication record 360 comprises a trace identifier (Id) and a time series entry (S). As such, the micro-service communication record 360 is defined as {Id,S}, a (3+D)-dimensional micro-service communication data. Each trace sequence identifier is given as: Id.sub.i={Id.sub.i.sup.1, Id.sub.i.sup.2, Id.sub.i.sup.3}, and is represented by a time stamp (Id.sub.i.sup.1=TS.sub.i) 361, a source cryptographic signature (Id.sub.i.sup.2=SCS.sub.i) 362, and a destination cryptographic signature (Id.sub.i.sup.3=DCS.sub.i) 363. Each time series entry is given as S.sub.i={S.sub.i.sup.1, S.sub.i.sup.2}, and is represented by a flow volume (S.sub.i.sup.1=FV.sub.i) 364, and a flow duration (S.sub.i.sup.2=FD.sub.i) 365. The time stamp 361 indicates when the micro-service communication record 360 was generated and can be used to determine the order/sequence of micro-service communications within the micro-service communication records. The source cryptographic signature 362 is the unique cryptographic signature (e.g., SHA-1, SHA-2, SHA-256) associated with the binary executable that sent the traffic associated with the micro-service communication record 360, while the destination cryptographic signature 363 is the unique cryptographic signature associated with the binary executable that received the traffic associated with the micro-service communication record 360. The flow volume 364 (FV.sub.i) is a 4-dimensional record that provides the number of packets/bytes transferred between the source and the destination, and the destination and the source. More specifically, as shown in FIG. 3B, the flow volume record 364 includes: entry 371 indicating the number of packets sent from the source to the destination, entry 372 indicating the number of packets sent from the destination to the source, entry 373 indicating the number of bytes sent from the source to the destination, and entry 374 indicating the number of bytes sent from the destination to the source. Finally, the flow duration 365 (FD.sub.i) identifies the duration of the communication exchange between pairs of executables. The time stamp 361, the flow volume 364, the flow duration 365, collectively represent a multivariate time series where {TS.sub.i, X.sub.i}={TS.sub.i, SCS.sub.i, DCS.sub.i, FV.sub.i, FD.sub.i} is a record representing the data communication exchange between source and destination nodes. [0039] The micro-service communication records are sent (e.g., via probes 158) to the micro-services monitoring module 144. As such, the micro-services monitoring module 144 receives a plurality of micro-service communication records (e.g., records 460(A), 460(B), and 460(C)). The micro-services monitoring module 144 is configured to analyze the time series entries S within the records to determine the behavior of the web application 150 during the associated time period and to analyze the trace sequence identifiers (forming a trace sequence) to determine the pattern of traffic between well identified source and destination nodes. The micro-services monitoring module 144 is further configured to determine whether the behavior of the web application 150, as indicated by the attributes of the micro-service communications (i.e., sending binary executable, receiving binary executable, sequence, volume, duration, etc.) between pairs of nodes at a given time, corresponds to expected behavior of the application. That is, the micro-services monitoring module 144 is able to infer global pattern of communications between executables running within the micro-services 134(1)-134(3) composing the application 150. In this way, the micro-services monitoring module 144 can detect possible anomalous behavior of the application 150 which, in turn, may indicate of security issues/problems affecting the application. [0044] Once the grammar generated by the reduced dynamical system is learned, the grammar, defining the structural features of the words produced by the linguistic source, is a complete model for the source. As such, it is possible to use the output of the dynamical system to predict its evolution or to find which control strings lead from one state to another. Any deviation not compatible with the learned grammar in the micro-service communication production from the nominal state, originates an anomaly determination/event. Here the described flow volume and trace sequence identify a source and a destination of the interactions between processes. Furthermore, the described deviation of normal/typical behavior and anomalous behavior is determining that first process does not interact with a second process. “Does not interact” has specific meaning in this claim; the previous step identifies "interactions" and "determines" that two processes "don't interact." The method identifies typical behavior process interactions (i.e., interactions) and then determine non-typical behavior process interactions (i.e., does not interact). It would have been obvious to one of ordinary skill in the art at the time of this application’s filing to introduce the ability to determine interactions (or lack thereof) between multiple processes (based on their respective source, destinations information) into Rappard’s design as it would allow for the identification of potential attack vectors. Rappard does not teach the following limitation in its entirety. f. and blocking, by the eBPF, interactions between the first process and the second process on the host network. Yannuzzi however, provides the missing element. Rappard provides a process for blocking a process on a network. Rappard, [0030] In one embodiment, a system, process, and/or computer program product for providing mobile network information sharing via eBPF for zero trust security includes blocking the session from accessing a resource based on the security policy. It would have been obvious to one of ordinary skill in the art at the time of this application’s filing to introduce the ability block interaction between processes into Rappard’s design as it would allow for the prevention of potential attacks. The reasoning cited for the rejection of Claim 1’s limitations extends to its child, Claim 2. Rappard does not explicitly teach the following limitation. 2. The method of claim 1, further comprising: a. determining, by the eBPF, a third process of the one or more processes operating on the host network interacts with the second process based on a source and a destination of the third process; Yannuzzi does however. [0117] In addition, the device may obtain an association between each of a plurality of workloads of an application service and a corresponding node executing that workload. The device may associate a verified node location to each of the plurality of workloads. The association between each of a plurality of workloads and the corresponding node executing that workload may include a unique ID of an association process that generated the association at the corresponding node. The association between each of a plurality of workloads and the corresponding node executing that workload may include a unique ID of a compliance process to enforce a data compliance policy at the corresponding node. The device may obtain the association between each of a plurality of workloads of the application service and the corresponding node executing that workload from a trusted authority or trusted authority federation. It would have been obvious to one of ordinary skill in the art at the time of this application’s filing to introduce the ability to determine interactions between a plurality of processes into Rappard’s design as it would allow for further monitoring, ensuring security compliance between processes. Rappard does not explicitly teach the following limitation. b. and injecting, by the eBPF, a security control between the second process and the third process. Yannuzzi does however. [0117] In addition, the device may obtain an association between each of a plurality of workloads of an application service and a corresponding node executing that workload. The device may associate a verified node location to each of the plurality of workloads. The association between each of a plurality of workloads and the corresponding node executing that workload may include a unique ID of an association process that generated the association at the corresponding node. The association between each of a plurality of workloads and the corresponding node executing that workload may include a unique ID of a compliance process to enforce a data compliance policy at the corresponding node It would have been obvious to one of ordinary skill in the art at the time of this application’s filing to introduce the ability to inject security controls between a plurality of processes into Rappard’s design as it would allow for further enforcement of security policies. The reasoning cited for the rejection of Claim 1’s limitations extends to its child, Claim 3. Rappard teaches the following substantially as claimed. 3. The method of claim 1, further comprising: a. identifying, by the eBPF, a query from the first process to the second process; determining, by the eBPF, the query from the first process to the second process is an attack based on the blocking of interactions between the first process and the second process; [0028] In some embodiments, a system, process, and/or computer program product for providing mobile network information sharing via eBPF for zero trust security includes monitoring network traffic in a core mobile network using an agent executed on a network element in the core mobile network to identify a session associated with a User Equipment (UE) that attached to the core mobile network for mobile network communications; extracting meta information associated with the session using the agent executed on a network element in the core mobile network; sending the extracted meta information to a security platform located outside of the core mobile network; and enforcing a security policy on the session at the security platform based on the extracted meta information to apply granular-based security in the core mobile network based on a security policy. [0030] In one embodiment, a system, process, and/or computer program product for providing mobile network information sharing via eBPF for zero trust security includes blocking the session from accessing a resource based on the security policy. [0060] At 258, various meta data (e.g., key meta, such as one or more of the example meta data that the eBPF client can extract as shown at 260 in FIG. 2E), such as Equipment Identifiers (IDs) (e.g., IMEI/PEI), Subscriber Identifiers (IDs) (e.g., IMSI/SUPI), DNN, Tracking Area Information (TAI) and/or User Location Information (ULI), and the IP address(es) that they map to are sent from the eBPF sensor to the security platform (e.g., security sensor/NFGW) for performing security policy enforcement (e.g., granular and/or zero trust security policy enforcement), such as similarly described above. b. and blocking, by the host network, the query from the first process from interacting with the second process. [0030] In one embodiment, a system, process, and/or computer program product for providing mobile network information sharing via eBPF for zero trust security includes blocking the session from accessing a resource based on the security policy. The reasoning cited for the rejection of Claim 3’s limitations extends to its child, Claim 5. Rappard teaches the following substantially as claimed. 5. The method of claim 3, a. wherein the query includes an encrypted data packet. [0035] As such, by using eBPF, the disclosed eBPF enabled sensors can also facilitate native support in Linux kernels and the ability to intercept 5G network activity even if that traffic is encrypted within the monitored mobile network environment. The reasoning cited for the rejection of Claim 1’s limitations extends to its child, Claim 6. Rappard does not explicitly teach the following limitation. 6. The method of claim 1, a. wherein the host network is a single server. Yannuzzi does however. [0025] As would be appreciated, network 100 may include any number of local networks, data centers, cloud environments, devices/nodes, servers, etc. It would have been obvious to one of ordinary skill in the art at the time of this application’s filing to allow Rappard’s design to operate in a single server environment into as this would in turn allow for the prevention of intra server attacks . Rappard teaches the following substantially as claimed. 8. A system comprising: a. a storage configured to store instructions; and a processor configured to execute the instructions and cause the processor to: [0014] The invention can be implemented in numerous ways, including as a process; an apparatus; a system; a composition of matter; a computer program product embodied on a computer readable storage medium; and/or a processor, such as a processor configured to execute instructions stored on and/or provided by a memory coupled to the processor. b. identify one or more processes operating on a host network; This limitation corresponds to limitation 1a and therefore inherits its rejection. c. assign, by the host network, a process identity to each of the one or more processes operating on the host network; This limitation corresponds to limitation 1b and therefore inherits its rejection. d. monitor, by an extended Berkeley Packet Filter (eBPF), interactions between each of the one or more processes operating on the host network; This limitation corresponds to limitation 1c and therefore inherits its rejection. e. identify, by the eBPF, a source and a destination of the interactions between each of the one or more processes operating on the host network; This limitation corresponds to limitation 1d and therefore inherits its rejection. Rappard does not explicitly teach the following limitation. f. determine, by the eBPF, a first process of the one or more processes operating on the host network does not interact with a second process of the one or more processes operating on the host network based on the source and the destination of the first process and the source and the destination of the second process; Yannuzzi does however. This limitation corresponds to limitation 1e and therefore inherits its rejection. Rappard does not teach the following limitation in its entirety. g. and block, by the eBPF, interactions between the first process and the second process on the host network. Yannuzzi however, provides the missing element. This limitation corresponds to limitation 1f and therefore inherits its rejection. The reasoning cited for the rejection of Claim 8’s limitations extends to its child, Claim 9. Rappard does not explicitly teach the following limitation. 9. The system of claim 8, further comprising: a. determining, by the eBPF, a third process of the one or more processes operating on the host network interacts with the second process based on a source and a destination of the third process; Yannuzzi does however. This limitation corresponds to limitation 2a and therefore inherits its rejection. Rappard does not explicitly teach the following limitation. b. and injecting, by the eBPF, a security control between the second process and the third process. Yannuzzi does however. This limitation corresponds to limitation 2b and therefore inherits its rejection. The reasoning cited for the rejection of Claim 8’s limitations extends to its child, Claim 10. Rappard teaches the following substantially as claimed. 10. The system of claim 8, further comprising: a. identifying, by the eBPF, a query from the first process to the second process; determining, by the eBPF, the query from the first process to the second process is an attack based on the blocking of interactions between the first process and the second process; This limitation corresponds to limitation 3a and therefore inherits its rejection. b. and blocking, by the host network, the query from the first process from interacting with the second process. This limitation corresponds to limitation 3b and therefore inherits its rejection. The reasoning cited for the rejection of Claim 10’s limitations extends to its child, Claim 12. Rappard teaches the following substantially as claimed. 12. The system of claim 10, a. wherein the query includes an encrypted data packet. This limitation corresponds to limitation 5a and therefore inherits its rejection. The reasoning cited for the rejection of Claim 8’s limitations extends to its child, Claim 13. Rappard does not explicitly teach the following limitation. 13. The system of claim 8, a. wherein the host network is a single server. Yannuzzi does however. This limitation corresponds to limitation 6a and therefore inherits its rejection. Rappard teaches the following substantially as claimed. 15. A non-transitory computer readable medium comprising instructions, the instructions, when executed by a computing system, cause the computing system to: a. identify one or more processes operating on a host network; assign, by the host network, a process identity to each of the one or more processes operating on the host network; This limitation corresponds to limitation 1a and therefore inherits its rejection. b. monitor, by an extended Berkeley Packet Filter (eBPF), interactions between each of the one or more processes operating on the host network; identify, by the eBPF, a source and a destination of the interactions between each of the one or more processes operating on the host network; This limitation corresponds to limitation 1b and therefore inherits its rejection. Rappard does not explicitly teach the following limitation. c. determine, by the eBPF, a first process of the one or more processes operating on the host network does not interact with a second process of the one or more processes operating on the host network based on the source and the destination of the first process and the source and the destination of the second process; Yannuzzi does however. This limitation corresponds to limitation 1c and therefore inherits its rejection. Rappard does not teach the following limitation in its entirety. d. and block, by the eBPF, interactions between the first process and the second process on the host network. Yannuzzi however, provides the missing element. This limitation corresponds to limitation 1d and therefore inherits its rejection. The reasoning cited for the rejection of Claim 15’s limitations extends to its child, Claim 16. Rappard does not explicitly teach the following limitation. 16. The non-transitory computer readable medium of claim 15, further comprising: a. determining, by the eBPF, a third process of the one or more processes operating on the host network interacts with the second process based on a source and a destination of the third process; Yannuzzi does however. This limitation corresponds to limitation 2a and therefore inherits its rejection. Rappard does not explicitly teach the following limitation. b. and injecting, by the eBPF, a security control between the second process and the third process. Yannuzzi does however. This limitation corresponds to limitation 2b and therefore inherits its rejection. The reasoning cited for the rejection of Claim 15’s limitations extends to its child, Claim 17 Rappard teaches the following substantially as claimed. 17. The non-transitory computer readable medium of claim 15, further comprising: a. identifying, by the eBPF, a query from the first process to the second process; determining, by the eBPF, the query from the first process to the second process is an attack based on the blocking of interactions between the first process and the second process; This limitation corresponds to limitation 3a and therefore inherits its rejection. b. and blocking, by the host network, the query from the first process from interacting with the second process. This limitation corresponds to limitation 3b and therefore inherits its rejection. The reasoning cited for the rejection of Claim 15’s limitations extends to its child, Claim 13. Rappard does not explicitly teach the following limitation. 19. The non-transitory computer readable medium of claim 15, a. wherein the host network is a single server. Yannuzzi does however. This limitation corresponds to limitation 6a and therefore inherits its rejection. Claim(s) 4,11,18 is/are rejected under 35 U.S.C. 103 as being unpatentable over 20240430680 A1, MOBILE NETWORK INFORMATION SHARING VIA EBPF FOR ZERO TRUST SECURITY, Rappard et. all, 2023-06-23 (Rappard hereafter) in view of US 20240039959 A1, COMPLIANT DATA TRANSFERS, Yannuzzi et. all, 2022-07-31 (Yannuzzi hereafter), 20190028496 A1, ANOMALY DETECTION FOR MICRO-SERVICE COMMUNICATIONS, Fenoglio et. all, 2022-07-31 (Fenoglio hereafter), as well as in further view of CN 109714292 B, Method And Device For Transmitting Message, LU, Sheng-wen, 2021-05-11 (LU herafter). The reasoning cited for the rejection of Claim 3’s limitations extends to its child, Claim 4. Rappard in view of Yannuzzi and in further view of Fenoglio does not teach the following limitation in its entirety. 4. The method of claim 3, further comprising: a. identifying, by the host network, an IP five-tuple of the query; and blocking the IP five-tuple from further interacting with the host network. LU however, provides the missing element. Rappard provides a process for blocking a process on a network. Rappard, [0030] In one embodiment, a system, process, and/or computer program product for providing mobile network information sharing via eBPF for zero trust security includes blocking the session from accessing a resource based on the security policy. LU provides the identification of an IP five-tuple of a query. LU, Page 17, Paragraph 3: when the accelerating card obtains the IP quintuple information of the TCP connection bearing the first TCP message from the received TCP message head of the first TCP message and the IP message head; the encryption information corresponding to the IP five-tuple information in the mapping relationship is determined as the encryption information for encrypting the first TCP message, so as to determine the length of the encryption block. It would have been obvious to one of ordinary skill in the art at the time of this application’s filing to introduce the ability to interpret an IP five-tuple formatting into Rappard’s design as it would allow for greater combability, ensuring further security compliance between processes. The reasoning cited for the rejection of Claim 10’s limitations extends to its child, Claim 11. Rappard in view of Yannuzzi and in further view of Fenoglio does not teach the following limitation in its entirety. 11. The system of claim 10, further comprising: a. identifying, by the host network, an IP five-tuple of the query; and blocking the IP five-tuple from further interacting with the host network. LU however, provides the missing element. This limitation corresponds to limitation 4a and therefore inherits its rejection. The reasoning cited for the rejection of Claim 17’s limitations extends to its child, Claim 18. Rappard in view of Yannuzzi does not teach the following limitation in its entirety. 18. The non-transitory computer readable medium of claim 17, further comprising: a. identifying, by the host network, an IP five-tuple of the query; and blocking the IP five-tuple from further interacting with the host network. LU however, provides the missing element. This limitation corresponds to limitation 4a and therefore inherits its rejection. Claim(s) 7,14,20 is/are rejected under 35 U.S.C. 103 as being unpatentable over 20240430680 A1, MOBILE NETWORK INFORMATION SHARING VIA EBPF FOR ZERO TRUST SECURITY, Rappard et. all, 2023-06-23 (Rappard hereafter) in view of US 20240039959 A1, COMPLIANT DATA TRANSFERS, Yannuzzi et. all, 2022-07-31 (Yannuzzi hereafter) as well as in further view of US 20160149764A1, PROVIDING VIRTUAL NETWORKING FUNCTIONALITY FOR MANAGED COMPUTER NETWORKS, Brandwine et all, 2016-05-26 (Brandwine hereafter). The reasoning cited for the rejection of Claim 1’s limitations extends to its child, Claim 7. Rappard in view of Yannuzzi and in further view of Fenoglio does not explicitly teach the following limitation. 7. The method of claim 1, a. wherein the host network is a virtual local area network (VLAN). Brandwine does however. [0009] Techniques are described for providing virtual networking functionality for managed computer networks, such as for computer networks that are managed and provided on behalf of users or other entities (e.g., by a network-accessible service). In at least some embodiments, the techniques enable a user to configure or otherwise specify one or more virtual local area networks for a managed computer network being provided for the user, such as with each specified virtual local area network (“VLAN”) including multiple computing nodes of the managed computer network (e.g., so as to separate the managed computer network into multiple logical sub-networks or other specified groups of computing nodes). It would have been obvious to one of ordinary skill in the art at the time of this application’s filing to allow for Rappard’s design to support a VLAN environment as it would in turn allow for the prevention of intra VLAN attacks. The reasoning cited for the rejection of Claim 8’s limitations extends to its child, Claim 14. Rappard in view of Yannuzzi and in further view of Fenoglio does not explicitly teach the following limitation. 14. The system of claim 8, a. wherein the host network is a virtual local area network (VLAN). Brandwine does however. This limitation corresponds to limitation 7a and therefore inherits its rejection. The reasoning cited for the rejection of Claim 15’s limitations extends to its child, Claim 20. Rappard in view of Yannuzzi and in further view of Fenoglio does not explicitly teach the following limitation. 20. The non-transitory computer readable medium of claim 15, a. wherein the host network is a virtual local area network (VLAN). Brandwine does however. This limitation corresponds to limitation 7a and therefore inherits its rejection. /LUCAS DONALD ABSHER/Examiner, Art Unit 2194 /KEVIN L YOUNG/Supervisory Patent Examiner, Art Unit 2194
Read full office action

Prosecution Timeline

Mar 20, 2024
Application Filed
Jul 21, 2026
Non-Final Rejection mailed — §101, §103 (current)

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month