DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
1. This Action is in response to applicant’s amendment filed on 07/09/2026.
2. Claims 1-20 are pending.
Response to Arguments
3. Applicant’s arguments and amendments filed on 07/09/2026 have been carefully considered but they are not deemed fully persuasive.
Applicant’s arguments include “Andrews's attack detection scheme does not rely on any "second computing system deployed in the on-premise network ... to decide whether to rate constrain the network traffic [at the CDN]," as recited in claim 1. Rather, as just discussed, Andrews's distribution-point servers of a CDN monitor and decide what to do at the CDN. Unsurprisingly, Andrews does not teach or suggest "a first computing system implementing a content distribution network (CDN) ... sending, to a second computing system deployed in the on-premise network, a request to decide whether to rate constrain the network traffic," as recited in claim 1.” And “identifying, by the first computing system, a particular one of a plurality of cached decisions associated with the network traffic, wherein the particular cached decision includes one of blocking the network traffic, permitting the network traffic to pass to the on- premise network, and issuing a challenge to a source of the network traffic”.
Examiner respectfully disagrees.
It is evident from the mappings found in the rejection below that Andrews shows “second computing system deployed in the on-premise network ... to decide whether to rate constrain the network traffic [at the CDN]” as para [0018] states “The distribution points 110 are geographically separated from one another. Each distribution point 110 includes one or more servers and may further include other machines such as load balancers (not shown).” Which reads on secondary computing system deployed on-premise network as the different on premise networks are geographically separated physically and attach to the CDN network at different levels and [0032] shows “Once the request rate at the first server exceeds the configured server level threshold, the process graduates the monitoring to the distribution point level. Specifically, the process next analyzes (at 230) the request rate for the distribution point in which the first server operates. In some embodiments, analyzing the distribution point request rate involves requesting, receiving, and aggregating the request rates from each server in the distribution point. In some other embodiments, analyzing the distribution point request rates involves monitoring and aggregating the request rate experienced by all servers in the distribution point. If the exceeded server level threshold is specific to particular content or one or more specific IP addresses, step 230 can be modified so as to analyze the aggregate request rate at the distribution point for the same particular content or same one or more IP addresses. As an example, if the request rate for “example.com/movie.flv” exceeds the configured server level threshold, the distribution point monitoring will aggregate the request rate for “example.com/movie.flv” at each server of the distribution point. In this example, the distribution point monitoring will not account for request rates for other content. As a different example, if the request rate for all requests received by a given server exceeds the configured server level threshold, the distribution point monitoring will then aggregate the request rate for all incoming requests received by all servers within the same distribution point.” which shows the analysis and threshold results are sent up the level for implementing the rate constraining. As for claim 19, the decision resulting from the analyzing process must be stored in cache in order to be transmitted to another system for implementing the rate constraining in Andrews, this is evidences from para [0021] showing “Different implementations utilize different traffic management schemes, such as Anycast routing or Domain Name System (DNS) routing, to achieve such routing. The traffic management server 120 operation can therefore facilitate failover and redundancy. However, such operation can also enable attacks from spilling-over from one distribution point to another.” which these schemes are for managing traffic such as blocking traffic, this view is supported further in Andrews showing specific schemes for rate limiting at [0049-0056]. Therefore, the 35 USC 102 rejection of the claims is respectfully maintained below.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
4. Claims 1-20 is rejected under 35 U.S.C. 102(a)(1) as being unpatentable over Andrews et al. (USPUB 2017/0180414 A1 from applicant’s IDS filed on 08/28/2025) hereinafter Andrews.
5. Regarding Claim 1, Andrews disclosed a non-transitory computer readable medium having program instructions stored therein that are executable by a first computing system implementing a content distribution network (CDN) to perform operations (see Fig.1, [0017-0018] and [0058]) comprising:
receiving, at the CDN, network traffic requesting access to a service associated with an on-premise network; sending, to a second computing system deployed in the on-premise network, a request to decide whether to rate constrain the network traffic, wherein the second computing system is configured to perform an analysis on the network traffic (see [0020-0023]);
in response to the request, receiving a decision from the second computing system; and implementing the decision for the network traffic at the CDN (see Fig.2, [0030-0032]).
6. Regarding Claim 2, Andrews disclosed the computer readable medium of claim 1, wherein the request is a request for the second computer system to determine whether the network traffic is associated with a denial of service attack (see [0014] and [0023]).
7. Regarding Claim 3, Andrews disclosed the computer readable medium of claim 1, wherein the decision includes one of blocking the network traffic, permitting the network traffic to pass to the on-premise network, and issuing a challenge to a source of the network traffic (see [0054]).
8. Regarding Claim 4, Andrews disclosed the computer readable medium of claim 3, wherein issuing the challenge includes: sending a challenge that asks for a response indicative of whether a human is present at the source; and based on the response, permitting the source to access the service (see [0020-0025]).
9. Regarding Claim 5, Andrews disclosed the computer readable medium of claim 1, wherein the decision specifies one or more internet protocol (IP) addresses applicable to the decision (see [0027]).
10. Regarding Claim 6, Andrews disclosed the computer readable medium of claim 1, wherein the decision specifies a time duration for which the decision is applicable; and wherein the implementing includes applying the decision to the network traffic for the specified time duration (see [0035]).
11. Regarding Claim 7, Andrews disclosed the computer readable medium of claim 1, further comprising: storing, at the CDN, the received decision in a cache including a plurality of decisions; in response to receiving additional network traffic, identifying a particular one of the decisions associated with the additional network traffic; and implementing the particular cached decision for the additional network traffic (see [0020]).
12. Regarding Claim 8, Andrews disclosed the computer readable medium of claim 1, wherein the operations further comprise: deploying, at the first computing system implementing the CDN, a container including a rate limiter application that sends the request to the second computing system deployed in the on-premise network and implements the decision for the network traffic at the CDN (see [0020-0027]).
13. Regarding Claim 9, Andrews disclosed the computer readable medium of claim 8, wherein the operations further comprise: receiving, at the container, the network traffic requesting access to the service; and rate constraining, by the container, the network traffic to implement the decision (see [0020-0027]).
14. Regarding Claim 10, Andrews disclosed the computer readable medium of claim 8, wherein the implementing includes: providing, by the container, one or more instructions to network hardware to rate constrain the network traffic in accordance with the decision (see [0020-0027]).
15. Regarding Claim 11, Andrews disclosed a non-transitory computer readable medium having program instructions stored therein that are executable by a first computing system implementing an on-premise network to perform operations (see Fig.1, [0017-0018] and [0058]) comprising:
receiving, from a second computer system implementing a content distribution network (CDN), a request to decide whether to rate constrain network traffic received at the CDN and requesting access to a service associated with the on-premise network; analyzing the network traffic to determine a decision indicating how to rate constrain the network traffic based on one or more criteria (see [0020-0023]); and sending the decision to the second computer system for implementation at the CDN (see Fig.2, [0030-0032]).
16. Regarding Claim 12, Andrews disclosed the computer readable medium of claim 11, wherein the sending includes: instructing the second computing system to perform one of blocking network traffic at the CDN, permitting the network traffic to pass to the on-premise network, and issuing a challenge to a source of the network traffic (see [0020-0023] and [0030-0032]).
17. Regarding Claim 13, Andrews disclosed the computer readable medium of claim 11, wherein the analyzing further includes: applying a machine learning algorithm to identify one or more patterns in the network traffic; and determining the decision based on the network traffic having the one or more patterns (see [0020-0023] and [0030-0032]).
18. Regarding Claim 14, Andrews disclosed the computer readable medium of claim 11, wherein the analyzing further includes: determining a frequency at which the network traffic is received from a source; and determining the decision based on the frequency satisfying a threshold (see [0020-0023] and [0030-0032]).
19. Regarding Claim 15, Andrews disclosed the computer readable medium of claim 11, wherein the analyzing further includes: applying a risk assessment algorithm to determine a risk score; and determining the decision based on the risk score satisfying a threshold (see [0020-0023] and [0030-0032]).
20. Regarding Claim 16, Andrews disclosed the computer readable medium of claim 11, wherein the analyzing further includes: maintaining a list indicative of whether particular network traffic is permitted to be received by the on-premise network; and determining the decision based on the list (see [0020-0023] and [0030-0032]).
21. Regarding Claim 17, Andrews disclosed the computer readable medium of claim 11 wherein the analyzing further includes: determining whether the network traffic is associated with a denial of service attack (see [0020-0023] and [0030-0032]).
22. Regarding Claim 18, Andrews disclosed the computer readable medium of claim 11 further comprising: tracking metrics pertaining to implementation of the received decision; and sending the metrics to a datastore of the on-premise network (see [0020-0023] and [0030-0032]).
23. Regarding Claim 19, Andrews disclosed a method, comprising: receiving, by a first computing system implementing a content distribution network (CDN), network traffic requesting access to a service associated with an on-premise network; identifying, by the first computing system, a particular one of a plurality of cached decisions associated with the network traffic, wherein the particular cached decision includes one of blocking the network traffic, permitting the network traffic to pass to the on-premise network, and issuing a challenge to a source of the network traffic; and implementing the particular cached decision for the network traffic at the CDN (see Fig.1,Fig.2, [0020-0023] and [0030-0032]).
24. Regarding Claim 20, Andrews disclosed the method of claim 19, further comprising: instantiating, at the first computing system implementing the CDN, a container including a rate limiter application that implements the decision for the network traffic at the CDN; receiving, at the container, network traffic requesting access to the service of the on-premise network; and rate constraining, by the container, the network traffic to implement the decision (see [0020-0023] and [0030-0032]).
Conclusion
Relevant Prior Art Not Relied Upon
The prior art made of record and not relied upon is considered pertinent to Applicant's disclosure. The additional cited art, including but not limited to the excerpts below, further establishes the state of the art at the time of Applicant’s invention and shows the following was known:
Methods, apparatus, systems, and articles of manufacture to protect proprietary functionality and/or other content in hardware and software are disclosed. An example computer apparatus includes; a first circuit including a first interface, the first circuit associated with a first domain; a second circuit including a second interface, the second circuit associated with a second domain; and a chip manager to generate a first authenticated interface for the first interface using a first token and to generate a second authenticated interface for the second interface using a second token to enable communication between the first authenticated interface and the second authenticated interface. (Cheruvu et al. ‘578)
Methods and apparatus to coordinate edge platforms are disclosed. A disclosed example apparatus includes to control processing of data associated with edges includes an orchestrator analyzer to determine a first performance requirement of a first microservice of an application and a second performance requirement of a second microservice of the application. The apparatus also includes an orchestrator controller to assign the first microservice and the second microservice across first and second edge nodes between a source network and a destination network by: assigning the first microservice to the first edge node based on a first capability of the first edge node satisfying the first performance requirement of the first microservice, and assigning the second microservice to the second edge node based on a second capability of the second edge node satisfying the second performance requirement of the second microservice. (Maciocco et al. ‘133)
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to DAVOUD ZAND whose telephone number is (571)272-2697, Fax (571) 273-2697. The examiner can normally be reached on Mon-Fri 9:30-5:30pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Oscar Louie can be reached on (571) 270-1684. The fax phone number for the organization where this application or proceeding is assigned is (571) 273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/DAVOUD A ZAND/Primary Examiner, Art Unit 2445