DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . This action is made non-final.
Claims 1-10 filed on 04/11/2024 have been reviewed and considered by this office action. Applicant’s election without traverse of claims 1-10 in the reply filed on 07/09/2026 is acknowledged.
Priority
Acknowledgment is made of applicant's claim for foreign priority under 35 U.S.C. 119 (a)-(d) based on Application No. KR10-2021-0153391 filed on 11/09/2021 and Application No. KR10-2021-0161700 filed on 11/22/2021. Copies of certified papers required by 37 CFR 1.55 have been received.
Information Disclosure Statement
The information disclosure statement filed on 04/11/2024 has been reviewed and considered by this office action.
Drawings
The drawings filed on 04/11/2024 have been reviewed and are considered acceptable.
Specification
The specification filed on 04/11/2024 has been reviewed and is considered acceptable.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-10 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more.
Step 1: Claims 1-5 are directed to a process. Claims 6-10 are directed to a machine or an article of manufacture.
With respect to claim 1:
2A Prong 1: The claim recites an abstract idea. Specifically:
by the cluster unit, creating a cluster by clustering the plurality of nodes; (Mental process – clustering a plurality of nodes is an evaluation that can be practically performed in the human mind, or by a human using a pen and paper as a physical aid – see MPEP § 2106.04(a)(2)(III))
by a label processor, deriving one or more connected components by performing connected component analysis on the created cluster; and (Mental process – deriving one or more connected components by performing connected component analysis is an evaluation that can be practically performed in the human mind, or by a human using a pen and paper as a physical aid – see MPEP § 2106.04(a)(2)(III))
2A Prong 2: The additional elements recited in the claim do not integrate the abstract idea into a practical application, individually or in combination.
Additional elements:
by a cluster unit, upon receiving a plurality of input data, forming a plurality of nodes by mapping the plurality of input data into a predetermined vector space; (Insignificant extra-solution activity (mere data gathering) – see MPEP § 2106.05(g))
by the label processor, performing labeling on the connected components. (Adding the words “apply it” (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP § 2106.05(f))
2B: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception.
Additional elements:
by a cluster unit, upon receiving a plurality of input data, forming a plurality of nodes by mapping the plurality of input data into a predetermined vector space; (Insignificant extra-solution activity (mere data gathering) – see MPEP § 2106.05(g))
by the label processor, performing labeling on the connected components. (Adding the words “apply it” (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP § 2106.05(f))
Therefore, the claim is ineligible.
With respect to claim 2:
2A Prong 1: The claim recites an abstract idea. Specifically:
wherein creating the cluster by clustering the plurality of nodes includes: by the cluster unit, calculating a node value of a node in the cluster and an edge value indicating a distance or correlation between one node and another node. (Mental process – calculating a node value and an edge value is an evaluation that can be practically performed in the human mind, or by a human using a pen and paper as a physical aid – see MPEP § 2106.04(a)(2)(III))
Therefore, the claim is ineligible.
With respect to claim 3:
2A Prong 1: The claim recites an abstract idea. Specifically:
wherein performing labeling on the connected components includes: by the label processor, determining a label for the connected component based on an average of edge values between the plurality of nodes included in the connected component. (Mental process – determining a label for a connected component based on an average of edge values is an evaluation that can be practically performed in the human mind, or by a human using a pen and paper as a physical aid – see MPEP § 2106.04(a)(2)(III))
Therefore, the claim is ineligible.
With respect to claim 4:
2A Prong 2: The additional elements recited in the claim do not integrate the abstract idea into a practical application, individually or in combination.
Additional elements:
wherein determining the label includes: in case where the edge value represents a distance between nodes in the vector space, by the label processor, assigning the label of the connected component with a lowest average of edge values between the nodes included in the connected component as normal (Adding the words “apply it” (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP § 2106.05(f))
2B: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception.
Additional elements:
wherein determining the label includes: in case where the edge value represents a distance between nodes in the vector space, by the label processor, assigning the label of the connected component with a lowest average of edge values between the nodes included in the connected component as normal (Performing repetitive calculations has been deemed a well‐understood, routine, and conventional function – see MPEP § 2106.05(d)(ll))
Therefore, the claim is ineligible.
With respect to claim 5:
2A Prong 2: The additional elements recited in the claim do not integrate the abstract idea into a practical application, individually or in combination.
Additional elements:
wherein determining the label includes: in case where the edge value represents a correlation between nodes in the vector space, by the label processor, assigning the label of the connected component with a highest average of edge values between the nodes included in the connected component as normal (Adding the words “apply it” (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP § 2106.05(f))
2B: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception.
Additional elements:
wherein determining the label includes: in case where the edge value represents a distance between nodes in the vector space, by the label processor, assigning the label of the connected component with a lowest average of edge values between the nodes included in the connected component as normal (Performing repetitive calculations has been deemed a well‐understood, routine, and conventional function – see MPEP § 2106.05(d)(ll))
Therefore, the claim is ineligible.
With respect to claim 6:
2A Prong 1: The claim recites an abstract idea. Specifically:
creating a cluster by clustering the plurality of nodes; and (Mental process – clustering a plurality of nodes is an evaluation that can be practically performed in the human mind, or by a human using a pen and paper as a physical aid – see MPEP § 2106.04(a)(2)(III))
a label processor deriving one or more connected components by performing connected component analysis on the created cluster, and (Mental process – deriving one or more connected components by performing connected component analysis is an evaluation that can be practically performed in the human mind, or by a human using a pen and paper as a physical aid – see MPEP § 2106.04(a)(2)(III))
2A Prong 2: The additional elements recited in the claim do not integrate the abstract idea into a practical application, individually or in combination.
Additional elements:
a cluster unit, upon receiving a plurality of input data, forming a plurality of nodes by mapping the plurality of input data into a predetermined vector space, and (Insignificant extra-solution activity (mere data gathering) – see MPEP § 2106.05(g))
performing labeling on the connected components (Adding the words “apply it” (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP § 2106.05(f))
2B: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception.
Additional elements:
a cluster unit, upon receiving a plurality of input data, forming a plurality of nodes by mapping the plurality of input data into a predetermined vector space, and (Insignificant extra-solution activity (mere data gathering) – see MPEP § 2106.05(g))
performing labeling on the connected components (Adding the words “apply it” (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP § 2106.05(f))
Therefore, the claim is ineligible.
With respect to claim 7:
2A Prong 1: The claim recites an abstract idea. Specifically:
wherein the cluster unit calculates a node value of a node in the cluster and an edge value indicating a distance or correlation between one node and another node. (Mental process – calculating a node value and an edge value is an evaluation that can be practically performed in the human mind, or by a human using a pen and paper as a physical aid – see MPEP § 2106.04(a)(2)(III))
Therefore, the claim is ineligible.
With respect to claim 8:
2A Prong 1: The claim recites an abstract idea. Specifically:
wherein the label processor determines a label for the connected component based on an average of edge values between the plurality of nodes included in the connected component (Mental process – determining a label for a connected component based on an average of edge values is an evaluation that can be practically performed in the human mind, or by a human using a pen and paper as a physical aid – see MPEP § 2106.04(a)(2)(III))
Therefore, the claim is ineligible.
With respect to claim 9:
2A Prong 2: The additional elements recited in the claim do not integrate the abstract idea into a practical application, individually or in combination.
Additional elements:
wherein in case where the edge value represents a distance between nodes in the vector space, the label processor assigns the label of the connected component with a lowest average of edge values between the nodes included in the connected component as normal. (Adding the words “apply it” (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP § 2106.05(f))
2B: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception.
Additional elements:
wherein in case where the edge value represents a distance between nodes in the vector space, the label processor assigns the label of the connected component with a lowest average of edge values between the nodes included in the connected component as normal. (Performing repetitive calculations has been deemed a well‐understood, routine, and conventional function – see MPEP § 2106.05(d)(ll))
Therefore, the claim is ineligible.
With respect to claim 10:
2A Prong 2: The additional elements recited in the claim do not integrate the abstract idea into a practical application, individually or in combination.
Additional elements:
wherein in case where the edge value represents a correlation between nodes in the vector space, the label processor assigns the label of the connected component with a highest average of edge values between the nodes included in the connected component as normal. (Adding the words “apply it” (or an equivalent) with the judicial exception, or mere instructions to implement an abstract idea on a computer, or merely uses a computer as a tool to perform an abstract idea – see MPEP § 2106.05(f))
2B: The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception.
Additional elements:
wherein in case where the edge value represents a correlation between nodes in the vector space, the label processor assigns the label of the connected component with a highest average of edge values between the nodes included in the connected component as normal. (Performing repetitive calculations has been deemed a well‐understood, routine, and conventional function – see MPEP § 2106.05(d)(ll))
Therefore, the claim is ineligible.
Claim Rejections - 35 USC § 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 1-3 and 6-8 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Guo et al. (US 2017/0091543 A1).
Regarding claim 1, Guo discloses a method for performing labeling, the method comprising:
by a cluster unit, upon receiving a plurality of input data, forming a plurality of nodes by mapping the plurality of input data into a predetermined vector space ([0193]: “A document d is represented as a vector Wd of term weights wt,d, which indicate the importance of each term t in the document”; [0268]: “No matter how the graph is constructed, however, the result is a graph containing nodes with each node representing a record”);
by the cluster unit, creating a cluster by clustering the plurality of nodes ([0269]: “At operation 2006 of the method 2000, clustering of nodes in the graph occurs… a set of clusters 2500, 2502, 2504 of nodes are derived”);
by a label processor, deriving one or more connected components by performing connected component analysis on the created cluster ([0222]: “In this greedy agglomerative clustering algorithm, each record is initialized to be a cluster of size one, and the process repeatedly discovers connected components by broadcasting local cluster centers”; [0224]: “Output: A set of connected components C ⊂ 2V”); and
by the label processor, performing labeling on the connected components ([0225]: “On convergence, vertices that have the same label are in the same connected component”; [0269]: “the labels for nodes 2606 and 2608 are changed to the label for node 2602 in graph 2610”).
Regarding claim 2, Guo discloses the method of claim 1.
Guo further discloses wherein creating the cluster by clustering the plurality of nodes includes: by the cluster unit, calculating a node value of a node in the cluster ([0234]: “The mapper reads the output of edge refinement and identifies all the vertices (organization records). The reducer assigns a unique label to every record and also find the degree of each vertex”; [0228]: “the merging function m is updated to find the vertex with the largest degree among the incoming messages and it is placed as the local cluster center”) and an edge value indicating a distance or correlation between one node and another node ([0266]: “The result is a graph with each node representing a record, and the similarity between examined record pairs represented as edges between nodes, with each edge assigned an edge score equal to the underlying similarity score for the record pair”; [0207]: “there is a need to further describe the distance between the discovered record pairs”).
Regarding claim 3, Guo discloses the method of claim 1.
Guo further discloses wherein performing labeling on the connected components includes: by the label processor, determining a label for the connected component based on an average of edge values between the plurality of nodes included in the connected component ([0243]: “For each datum i, let a(i) be the average dissimilarity of i with all other data within the same cluster”; [0270]: “The result may be a cluster quality score for each cluster”; [0248]: “The average s(i) over all data of a cluster is a measure of how tightly grouped all the data in the cluster are. Thus, the average s(i) over all data of the entire dataset is a measure of how appropriately the data has been clustered”; [0249]: “Thus, the cluster-level index helps assess the quality of each cluster,” where the cluster-level index corresponds to a label).
Regarding claim 6, Guo discloses a device for performing labeling, the device comprising:
a cluster unit, upon receiving a plurality of input data, forming a plurality of nodes by mapping the plurality of input data into a predetermined vector space ([0193]: “A document d is represented as a vector Wd of term weights wt,d, which indicate the importance of each term t in the document”; [0268]: “No matter how the graph is constructed, however, the result is a graph containing nodes with each node representing a record”), and creating a cluster by clustering the plurality of nodes ([0269]: “At operation 2006 of the method 2000, clustering of nodes in the graph occurs… a set of clusters 2500, 2502, 2504 of nodes are derived”); and
a label processor deriving one or more connected components by performing connected component analysis on the created cluster ([0222]: “In this greedy agglomerative clustering algorithm, each record is initialized to be a cluster of size one, and the process repeatedly discovers connected components by broadcasting local cluster centers”; [0224]: “Output: A set of connected components C ⊂ 2V”), and
performing labeling on the connected components ([0225]: “On convergence, vertices that have the same label are in the same connected component”; [0269]: “the labels for nodes 2606 and 2608 are changed to the label for node 2602 in graph 2610”).
Regarding claim 7, Guo discloses the device of claim 6.
Guo further discloses wherein the cluster unit calculates a node value of a node in the cluster ([0234]: “The mapper reads the output of edge refinement and identifies all the vertices (organization records). The reducer assigns a unique label to every record and also find the degree of each vertex”; [0228]: “the merging function m is updated to find the vertex with the largest degree among the incoming messages and it is placed as the local cluster center”) and an edge value indicating a distance or correlation between one node and another node ([0266]: “The result is a graph with each node representing a record, and the similarity between examined record pairs represented as edges between nodes, with each edge assigned an edge score equal to the underlying similarity score for the record pair”; [0207]: “there is a need to further describe the distance between the discovered record pairs”).
Regarding claim 8, Guo discloses the device of claim 6.
Guo further discloses wherein the label processor determines a label for the connected component based on an average of edge values between the plurality of nodes included in the connected component ([0243]: “For each datum i, let a(i) be the average dissimilarity of i with all other data within the same cluster”; [0270]: “The result may be a cluster quality score for each cluster”; [0248]: “The average s(i) over all data of a cluster is a measure of how tightly grouped all the data in the cluster are. Thus, the average s(i) over all data of the entire dataset is a measure of how appropriately the data has been clustered”; [0249]: “Thus, the cluster-level index helps assess the quality of each cluster,” where the cluster-level index corresponds to a label).
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 4 and 9 are rejected under 35 U.S.C. 103 as being unpatentable over Guo et al. (US 2017/0091543 A1), in view of Lee et al. (KR 20150091775 A) (Note: a machine translation is used for mapping, attached to this action).
Regarding claim 4, Guo discloses the method of claim 3.
Guo further teaches wherein determining the label includes: in case where the edge value represents a distance between nodes in the vector space, by the label processor, assigning the label of the connected component with a lowest average of edge values between the nodes included in the connected component ([0243]: “For each datum i, let a(i) be the average dissimilarity of i with all other data within the same cluster. a(i) can be interpreted as how well i is assigned to its cluster (the smaller the value, the better the assignment)”; [0244]: “Let b(i) be the lowest average dissimilarity of i to any other cluster of which i is not a member. The cluster with this lowest average dissimilarity is said to be the 'neighboring cluster' of i because it is the next best-fit cluster for point i”; [0247]: “For s(i) to be close to 1, a(i)<<b(i), As a(i) is a measure of how dissimilar i is to its own cluster, a small value means it is well matched”).
Guo therefore teaches that a small average distance/dissimilarity corresponds to a better cluster assignment. Guo, however, does not explicitly teach assigning the label as “normal.”
Lee further teaches assigning the label as normal ([0022]: “cluster analysis unit 231 that analyzes the shape of a cluster to detect outliers (or abnormal hosts) that do not belong to the cluster”; [0032]: “As a result of clustering, it is possible to detect clusters and outliers that do not belong to a cluster”; [0053]: “The analysis system 200 can analyze the result data after clustering in S711 and extract hosts with abnormal data that are not included in the cluster”; [0050]: “it is also possible to identify if a specific host (e.g., Host #1) moves from the normal host area to the abnormal host area over time”).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to adapt the method of Guo to incorporate the teachings of Lee so as to include assigning the label as normal. Doing so would allow a connected component satisfying a clustering criterion to be designated as normal with the aim of distinguishing normal behavior from abnormal behavior (Lee, [0004]: “In the case of existing rule-based network intrusion detection systems, rules are defined based on known attacks or malicious behaviors, and external intrusions are recognized by these rules; therefore, they cannot detect unknown new types of attacks or malicious behaviors disguised as normal behaviors”).
Regarding claim 9, Guo discloses the device of claim 8.
Guo further teaches wherein in case where the edge value represents a distance between nodes in the vector space, the label processor assigns the label of the connected component with a lowest average of edge values between the nodes included in the connected component ([0243]: “For each datum i, let a(i) be the average dissimilarity of i with all other data within the same cluster. a(i) can be interpreted as how well i is assigned to its cluster (the smaller the value, the better the assignment)”; [0244]: “Let b(i) be the lowest average dissimilarity of i to any other cluster of which i is not a member. The cluster with this lowest average dissimilarity is said to be the 'neighboring cluster' of i because it is the next best-fit cluster for point i”; [0247]: “For s(i) to be close to 1, a(i)<<b(i), As a(i) is a measure of how dissimilar i is to its own cluster, a small value means it is well matched”).
Guo therefore teaches that a small average distance/dissimilarity corresponds to a better cluster assignment. Guo, however, does not explicitly teach assigning the label as “normal.”
Lee further teaches assigning the label as normal ([0022]: “cluster analysis unit 231 that analyzes the shape of a cluster to detect outliers (or abnormal hosts) that do not belong to the cluster”; [0032]: “As a result of clustering, it is possible to detect clusters and outliers that do not belong to a cluster”; [0053]: “The analysis system 200 can analyze the result data after clustering in S711 and extract hosts with abnormal data that are not included in the cluster”; [0050]: “it is also possible to identify if a specific host (e.g., Host #1) moves from the normal host area to the abnormal host area over time”).
The reasons to combine Lee into Guo are the same as articulated in claim 4 above.
Claims 5 and 10 are rejected under 35 U.S.C. 103 as being unpatentable over Guo et al. (US 2017/0091543 A1), in view of Lee et al. (KR 20150091775 A), and in view of Mallik (Mallik, Saurav, and Zhongming Zhao. "Detecting methylation signatures in neurodegenerative disease by density-based clustering of applications with reducing noise." Scientific reports 10.1 (2020): 22164.).
Regarding claim 5, Guo discloses the method of claim 3.
Guo does not explicitly teach “wherein determining the label includes: in case where the edge value represents a correlation between nodes in the vector space, by the label processor, assigning the label of the connected component with a highest average of edge values between the nodes included in the connected component as normal.”
Mallik further teaches wherein determining the label includes: in case where the edge value represents a correlation between nodes (Page 5: “we first estimated the power value of soft-thresholding, and then used the power to compute the adjacency matrix using Pearson’s correlation. Then the TOM score was computed and distance score was determined. Next, average linkage clustering and dynamic tree cut methods were used to identify gene modules”) in the vector space (Page 5: “ obtained a unique methylation data vector for each gene”), by the label processor, assigning the label of the connected component with a highest average of edge values between the nodes included in the connected component (Page 3: “Pearson’s correlation coefficient (PCC) was computed among each gene-pair belonging to each gene module. Finally, the average correlation score for each cluster was obtained. The cluster that had the highest average PCC, was selected as the potential gene signature consisting of all differentially methylated genes”).
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to adapt the method of Guo to incorporate the teachings of Mallik so as to include determining the label including: in case where the edge value represents a correlation between nodes in the vector space, by the label processor, assigning the label of the connected component with a highest average of edge values between the nodes included in the connected component. Doing so would allow a connected component having a high correlation to be selected as a representative signature with the aim of achieving high classification accuracy (Mallik, Page 1: “Our evaluation indicated that these two signatures could lead to high classification accuracy values (92% and 70%)”).
Mallik does not explicitly teach assigning the label as normal.
Lee further teaches assigning the label as normal ([0022]: “cluster analysis unit 231 that analyzes the shape of a cluster to detect outliers (or abnormal hosts) that do not belong to the cluster”; [0053]: “The analysis system 200 can analyze the result data after clustering in S711 and extract hosts with abnormal data that are not included in the cluster”; [0050]: “it is also possible to identify if a specific host (e.g., Host #1) moves from the normal host area to the abnormal host area over time”).
The reasons to combine Lee into Guo in view of Mallik are the same as articulated in claim 4 above.
Regarding claim 10, Guo discloses the device of claim 8.
Guo does not explicitly teach “wherein in case where the edge value represents a correlation between nodes in the vector space, the label processor assigns the label of the connected component with a highest average of edge values between the nodes included in the connected component as normal.”
Mallik further teaches wherein in case where the edge value represents a correlation between nodes (Page 5: “we first estimated the power value of soft-thresholding, and then used the power to compute the adjacency matrix using Pearson’s correlation. Then the TOM score was computed and distance score was determined. Next, average linkage clustering and dynamic tree cut methods were used to identify gene modules”) in the vector space (Page 5: “ obtained a unique methylation data vector for each gene”), the label processor assigns the label of the connected component with a highest average of edge values between the nodes included in the connected component (Page 3: “Pearson’s correlation coefficient (PCC) was computed among each gene-pair belonging to each gene module. Finally, the average correlation score for each cluster was obtained. The cluster that had the highest average PCC, was selected as the potential gene signature consisting of all differentially methylated genes”).
The reasons to combine Guo into Mallik are the same as articulated in claim 5 above.
Mallik does not explicitly teach assigning the label as normal.
Lee further teaches assigning the label as normal ([0022]: “cluster analysis unit 231 that analyzes the shape of a cluster to detect outliers (or abnormal hosts) that do not belong to the cluster”; [0053]: “The analysis system 200 can analyze the result data after clustering in S711 and extract hosts with abnormal data that are not included in the cluster”; [0050]: “it is also possible to identify if a specific host (e.g., Host #1) moves from the normal host area to the abnormal host area over time”).
The reasons to combine Lee into Guo in view of Mallik are the same as articulated in claim 4 above.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
US 2012/0106925 A1: Clustering based on similarity
US 2016/0283817 A1: Clustering connected components
US 2014/0096249 A1: Anomaly detection based on clustering
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Magdalena Kossek whose telephone number is (571)272-5603. The examiner can normally be reached Mon-Fri 8:00-5:00 EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Robert Fennema can be reached at (571)272-2748. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/M.I.K./Examiner, Art Unit 2117
/ROBERT E FENNEMA/Supervisory Patent Examiner, Art Unit 2117