DETAILED ACTION
This office action is in response to the amendments filed on 08/05/2026.
Claims 1-20 have been amended.
Claims 1-20 are presented for examination.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 07/03/2026, 07/06/2026, and 08/05/2026 are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Response to Arguments
Applicant’s arguments, see Remarks pg. 7-9, filed 07/03/2026, with respect to 35 USC 101 abstract idea rejections have been fully considered and are persuasive. The 35 USC 101 abstract idea rejections has been withdrawn.
35 USC 101 abstract idea rejection is removed in view of Applicant Remarks pg. 9 filed 07/03/2026 regarding improving computer functionality tied to reduction of resources needed to perform attack surface analysis in para.0022 and para.0025 by comparing to the timestamped scan of ip addresses.
Applicant’s arguments with respect to claim(s) 35 USC 102 and 35 USC 103 rejections filed on 07/03/2026 in Remarks pg. 9-13 have been considered but are moot because the new ground of rejection does not rely on any reference applied in the prior rejection of record for any teaching or matter specifically challenged in the argument.
Applicant further argues in essence:
[a] “Moreover, there are other glaring distinctions. Again, as this Reply above explains, Huang with Cross determines "asset discovery without active scanning and without using an inventory list." See U.S. Patent Application Publication 2023/0344848 to Huang, et al. at paragraph [0028] (emphasis added). Independent claim 15, in contradistinction, recites a "timestamped domain scan of Internet Protocol (IP) addresses associated with a domain name." Because Huang with Cross expressly eschews these claimed features, an ordinary person skilled in the art would not find independent claim 15 obvious.”
In response to [a], examiner respectfully disagrees. While examiner rejects the claims with a different combination of references, Huang is still relied upon as a primary reference for several limitations. Under broadest reasonable interpretation, "timestamped domain scan of Internet Protocol (IP) addresses associated with a domain name." is a scan of IP addresses that are associated to at least a domain name, which are also timestamped. In the case of Huang below, a scan of the threat data store is performed, which have domain names, and timestamps in para.0048 and para.0051 below. Therefore under broadest reasonable interpretation, Huang still reads on these limitations, and does not teach away as inferred by the argument above.
In order to overcome this interpretation, examiner suggests incorporating a positive limitation describing the timestamp to be when the domain scan was performed rather than just being a timestamped scan and the timeframe to reflect this change, and the domain scan to be limited to a domain.
Huang: Para.0051 “ For example, log-threat correlation module 202 scans a list of malicious indicators in threat data store 212 and compares each entry to each network log in the network traffic log store 210 that is associated with the client domain 110. If there is a match between a malicious indicator from threat data store 212 and an identifier found in a network traffic log for client domain 110 (e.g., matching IP address, domain name, or other unique identifier or network address), then the identifier found in the network traffic log is determined to be a malicious indicator.”
Para.0048 “Threat data store 212 stores data for identifying threats. The data may include “threat data feeds.” A used herein, a “threat data feed” may refer to a set of data corresponding to threats, including lists of malicious indicators and data associated with the malicious indicators, such as indicator attributes, including time of threats”
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1, 4-5, 7-8, 11-12 14 is/are rejected under 35 U.S.C. 103 as being unpatentable over Huang et al. (hereinafter Huang US 2023/0344848 A1) in view of Ahn et al. (hereinafter Ahn, US 2022/0014538 A1).
Regarding Claim 1, Huang discloses A method executed by a computer system that identifies a device exposed to a public Internet (Huang: para.0003 “As described herein, systems and methods for managing an attack surface are provided. The systems and methods involve an “inside-out” analysis of network traffic flowing into and out of the organization's domain. Using machine intelligence, the most critical vulnerabilities can be identified and addressed in an efficient manner.” Para.0028 “ In asset discovery, internet-facing assets of an organization can be determined without active scanning and without using an inventory list.” Systems that perform a method for determining internet facing assets.), comprising:
receiving, by the computer system providing an external attack surface management service (Huang: Computing System 220 comprising attack surface management engine identifying external facing assets. Para.0067 “hosts of client domain 110 that are exposed to an external network 130 (e.g., the internet)”),
a timestamped message reported by a cybersecurity sensory agent monitoring the device (Huang: para.0082 “The processor obtains 901 network traffic logs for a client domain 110. In one embodiment a user of user device 240 may provide (e.g., upload) the network traffic logs 220A for the client domain 110 to the computing system 220, or to a database 250 accessible by the computing system 220, via external network 230. In another embodiment, computing system 220 may actively monitor the network traffic of client domain 110 to obtain the network traffic logs 220A.” para.0047 “ The network traffic logs may comprise timestamps indicating times when each message in a network traffic log was transmitted and received, as well as timestamps for when each network traffic log was obtained by the computing system 220. Furthermore, the network traffic logs may comprise identifiers for the entity (e.g., host) that sent or received the message, and an identifier for the entity where the network traffic log was obtained from. For example, the identifiers may include unique identifiers for each client domain 110, user device 240, and/or user of a user device 240, such as a user profile identifier (ID) stored in database 250 that is correlated to the user device 240 or client domain 110 (e.g., a User ID for an admin of client domain 110).” a connection notification, the network traffic logs comprising information regarding connectivity between entities as messages are sent between each entity, are reported by the user device 240, the software of user device 240 being the cybersecurity sensory agent monitoring communication of the device as it generates traffic logs. The attack surface management engine, para.0032, obtains this information from the software of the user device 240.);
determining, by the computer system providing the external attack surface management service, an Internet Protocol (IP) address match occurring within a timeframe between the timestamped message reported by the cybersecurity sensory agent monitoring the device and a timestamped scan of IP addresses associated with the public Internet (Huang: Para.0051 “ For example, log-threat correlation module 202 scans a list of malicious indicators in threat data store 212 and compares each entry to each network log in the network traffic log store 210 that is associated with the client domain 110. If there is a match between a malicious indicator from threat data store 212 and an identifier found in a network traffic log for client domain 110 (e.g., matching IP address, domain name, or other unique identifier or network address), then the identifier found in the network traffic log is determined to be a malicious indicator.” Para.0048 “Threat data store 212 stores data for identifying threats. The data may include “threat data feeds.” A used herein, a “threat data feed” may refer to a set of data corresponding to threats, including lists of malicious indicators and data associated with the malicious indicators, such as indicator attributes, including time of threats” ip address matches are performed with a scan of the threat data store, which is timestamped. This match occurs within a timeframe of the message being reported and the scan, as the match would have to occur after the message is reported and during the scan.); and
in response to the IP address match occurring within the timeframe between the message and the timestamped scan of the IP addresses associated with the public Internet, identifying, by the computer system providing the external attack surface management service, the device as the exposed to the public Internet (Huang: para.0085 “The processor determines 904 an exposed set of host identifiers based on the mapped flow of network traffic mapped at step 903. The processor determines the exposed set of host identifiers by determining host nodes having inbound traffic from at least one indicator node. The exposed set of host identifiers identifies hosts that form an attack surface of the client domain 110.” para.0028 “ Furthermore, the system determines which ports of the hosts may be exposed (e.g., to the internet) on these assets.” Para.0020 “As used herein an “asset,” may refer to a physical or virtual device that can send and receive data. For example, an asset may be a client or a server that sends and receives applications, services, other data, or some combination thereof. A “network host,” “host,” or “host asset” may refer to an asset that communicates with other assets through a particular network or domain (i.e., communicates with other hosts of the domain).” Devices, i.e. the devices associated with the identified hosts, exposed to the public internet are identified via the domain scan as in para.0082 Fig. 9 902-905. These devices are exposed to the public internet between the time frame of obtaining of the network logs and the scan of network addresses, as the scan itself it a process in which matches of the identifiers, such as addresses, are determined).
However Huang does not explicitly disclose SYN-ACK message, being in the network logs.
Ahn discloses a SYN-ACK message (Ahn: para.0024 “timestamp” para.0030 “Proxy device 112 may utilize the parameters to generate packets comprising data configured to establish a connection between proxy device 112 and host 106 (e.g., a TCP: SYN-ACK handshake message) and, at step #12, may communicate the packets to host 106. Rules 212 may be configured to cause rule gate 120 to one or more of identify the packets, determine (e.g., based on one or more network addresses included in their network-layer headers) that the packets comprise data corresponding to the network-threat indicators, for example, by correlating the packets with one or more of the packets comprising the DNS query or the reply to the DNS query based on data stored in logs 214 (e.g., the log data generated by rule gate 126 in one or more of steps # 6 or #7), and one or more of log or drop the packets.” Para.0020 “The threat-intelligence reports may include one or more network-threat indicators, for example, domain names (e.g., fully qualified domain names (FQDNs)), URIs, network addresses, or the like.” SYN-ACK packets are intercepted and checked for network threat indicators such as network address matches.)
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Huang with Ahn in order to incorporate a SYN-ACK message, and apply this concept to Huang such that SYN-ACK messages are considered in the network logs for identifying exposed assets.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved security (Ahn: para.0002).
Regarding Claim 4, Huang teaches claim 1 as set forth above.
Huang further discloses wherein the identifying of the device as the exposed to the public Internet further comprises determining a source port specified by both the timestamped message and the timestamped scan of the IP addresses associated with the public Internet. (Huang: para.0028 “ Furthermore, the system determines which ports of the hosts may be exposed (e.g., to the internet) on these assets.” Para.0048 “Threat data store 212 stores data for identifying threats. The data may include “threat data feeds.” A used herein, a “threat data feed” may refer to a set of data corresponding to threats, including lists of malicious indicators and data associated with the malicious indicators, such as … destination and source ports,” para.0051 “For example, log-threat correlation module 202 scans a list of malicious indicators in threat data store 212 and compares each entry to each network log in the network traffic log store 210 that is associated with the client domain 110. If there is a match between a malicious indicator from threat data store 212 and an identifier found in a network traffic log for client domain 110 (e.g., matching IP address, domain name, or other unique identifier or network address), then the identifier found in the network traffic log is determined to be a malicious indicator.” Para.0083 “The processor correlates 902 the network traffic logs to threat data. The processor correlates the network traffic logs 220A with threat data feeds from threat data store 212 to identify malicious indicators and to identify host identifiers communicating with the malicious indicators in the network traffic logs 220A. The identified host identifiers identify the hosts of the client domain 110.” para.0047 “ The network traffic logs may comprise timestamps indicating times when each message in a network traffic log was transmitted and received” Para.0048 “Threat data store 212 stores …, including time of threats” Based on matching source and destination ports from the logs to the threat data store, assets that are internet facing may be identified.).
However Huang does not explicitly disclose SYN-ACK message.
Ahn discloses a SYN-ACK message (Ahn: para.0024 “timestamp” para.0030 “Proxy device 112 may utilize the parameters to generate packets comprising data configured to establish a connection between proxy device 112 and host 106 (e.g., a TCP: SYN-ACK handshake message) and, at step #12, may communicate the packets to host 106. Rules 212 may be configured to cause rule gate 120 to one or more of identify the packets, determine (e.g., based on one or more network addresses included in their network-layer headers) that the packets comprise data corresponding to the network-threat indicators, for example, by correlating the packets with one or more of the packets comprising the DNS query or the reply to the DNS query based on data stored in logs 214 (e.g., the log data generated by rule gate 126 in one or more of steps # 6 or #7), and one or more of log or drop the packets.” Para.0020 “The threat-intelligence reports may include one or more network-threat indicators, for example, domain names (e.g., fully qualified domain names (FQDNs)), URIs, network addresses, or the like.” SYN-ACK packets are intercepted and checked for network threat indicators such as network address matches.)
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Huang with Ahn in order to incorporate a SYN-ACK message, and apply this concept to Huang such that SYN-ACK messages are considered in the network logs for identifying exposed assets.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved security (Ahn: para.0002).
Regarding Claim 5, Huang discloses claim 1 as set forth above.
Huang further discloses wherein the identifying of the device as the exposed to the public Internet further comprises determining a destination port specified by both the timestamped message and the timestamped scan of the IP addresses associated with the public Internet (Huang: para.0028 “ Furthermore, the system determines which ports of the hosts may be exposed (e.g., to the internet) on these assets.” Para.0048 “Threat data store 212 stores data for identifying threats. The data may include “threat data feeds.” A used herein, a “threat data feed” may refer to a set of data corresponding to threats, including lists of malicious indicators and data associated with the malicious indicators, such as … destination and source ports,” para.0051 “For example, log-threat correlation module 202 scans a list of malicious indicators in threat data store 212 and compares each entry to each network log in the network traffic log store 210 that is associated with the client domain 110. If there is a match between a malicious indicator from threat data store 212 and an identifier found in a network traffic log for client domain 110 (e.g., matching IP address, domain name, or other unique identifier or network address), then the identifier found in the network traffic log is determined to be a malicious indicator.” Para.0083 “The processor correlates 902 the network traffic logs to threat data. The processor correlates the network traffic logs 220A with threat data feeds from threat data store 212 to identify malicious indicators and to identify host identifiers communicating with the malicious indicators in the network traffic logs 220A. The identified host identifiers identify the hosts of the client domain 110.” para.0047 “ The network traffic logs may comprise timestamps indicating times when each message in a network traffic log was transmitted and received” Para.0048 “Threat data store 212 stores …, including time of threats” Based on matching source and destination ports from the logs to the threat data store, assets that are internet facing may be identified.).
However Huang does not explicitly disclose SYN-ACK message.
Ahn discloses a SYN-ACK message (Ahn: para.0024 “timestamp” para.0030 “Proxy device 112 may utilize the parameters to generate packets comprising data configured to establish a connection between proxy device 112 and host 106 (e.g., a TCP: SYN-ACK handshake message) and, at step #12, may communicate the packets to host 106. Rules 212 may be configured to cause rule gate 120 to one or more of identify the packets, determine (e.g., based on one or more network addresses included in their network-layer headers) that the packets comprise data corresponding to the network-threat indicators, for example, by correlating the packets with one or more of the packets comprising the DNS query or the reply to the DNS query based on data stored in logs 214 (e.g., the log data generated by rule gate 126 in one or more of steps # 6 or #7), and one or more of log or drop the packets.” Para.0020 “The threat-intelligence reports may include one or more network-threat indicators, for example, domain names (e.g., fully qualified domain names (FQDNs)), URIs, network addresses, or the like.” SYN-ACK packets are intercepted and checked for network threat indicators such as network address matches.)
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Huang with Ahn in order to incorporate a SYN-ACK message, and apply this concept to Huang such that SYN-ACK messages are considered in the network logs for identifying exposed assets.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved security (Ahn: para.0002).
Regarding Claim 7, Huang discloses claim 1 as set forth above.
Huang further discloses wherein the identifying of the device as the exposed to the public Internet further comprises determining a public network address and a port associated with the device (Huang: para.0019 “As such, the attack surface may comprise identifiers for each entry point, such as host identifiers (hosts IDs), port identifiers, device identifiers, combinations thereof, and the like.” para.0074 “ The dashboard may provide contents generated from prioritized attack surface data structure 221A. Entries of a report (e.g., report 401 or report 402), such as entries with private IP addresses, may be investigated using dashboard 403. Inbound traffic may not be expected to private IP addresses, which if detected, may indicate that a firewall is misconfigured and allowing traffic from a known indicator of compromise. A user of user device 240 (e.g., an analyst) can gain further insight into this host using dashboard 403, as shown in the following example. The event data about hosts 10.244.74.35 and 10.256.255.12 is automatically correlated with threat intelligence and asset enrichment.” Para.0028 “Furthermore, the system determines which ports of the hosts may be exposed (e.g., to the internet) on these assets.” The address and ports of the exposed hosts are identified.).
Regarding Claim 8 Huang discloses A computer system that identifies a device exposed to a public Internet (Huang: para.0003 “As described herein, systems and methods for managing an attack surface are provided. The systems and methods involve an “inside-out” analysis of network traffic flowing into and out of the organization's domain. Using machine intelligence, the most critical vulnerabilities can be identified and addressed in an efficient manner.” Para.0028 “ In asset discovery, internet-facing assets of an organization can be determined without active scanning and without using an inventory list.” Systems that perform a method for determining internet facing assets.), comprising:
at least one central processing unit; and a memory device storing instructions that, when executed by the at least one central processing unit, perform operations (Huang: para.0031 “Computing system 220 performs computational tasks, including tasks for discovering, prioritizing, and managing assets that form an attack surface of client domain 110. The computational tasks may be performed by a processor of computing system 220 that executes instructions in the form of computer-readable code stored on a computer-readable medium, such as a memory device.” The computing system that comprises attack surface management engine 221 in Fig. 2-3, comprising memory and processor executing instructions), the operations comprising:
receiving a timestamped message reported by a cybersecurity sensory agent monitoring the device (Huang: para.0082 “The processor obtains 901 network traffic logs for a client domain 110. In one embodiment a user of user device 240 may provide (e.g., upload) the network traffic logs 220A for the client domain 110 to the computing system 220, or to a database 250 accessible by the computing system 220, via external network 230. In another embodiment, computing system 220 may actively monitor the network traffic of client domain 110 to obtain the network traffic logs 220A.” a connection notification, the network traffic logs, are reported by the user device 240, the software of user device 240 being the cybersecurity sensory agent monitoring communication of the device as it generates traffic logs. The attack surface management engine, para.0032, obtains this information from the user device 240.);
determining an Internet Protocol (IP) address match (Huang: para.0051 “If there is a match between a malicious indicator from threat data store 212 and an identifier found in a network traffic log for client domain 110 (e.g., matching IP address, domain name, or other unique identifier or network address), then the identifier found in the network traffic log is determined to be a malicious indicator.” By the correlation determining a match from the traffic logs and threat data store, exposed ports/assets may be identified.)
and a port match (Huang: para.0028 “ Furthermore, the system determines which ports of the hosts may be exposed (e.g., to the internet) on these assets.” Para.0054 “For example, attribute determination module 205 may retrieve attributes associated with each host identifier in the exposed set from database 250, such as services associated with ports of the host identifier, a criticality level associated with the host identifier (e.g., as designated by an admin of the client domain 110), vulnerabilities associated with the host identifier, level of criticality associated with the vulnerabilities, other host attributes for generating values of a feature vector for the host identifier, or some combination thereof.” Para.0048 “including lists of malicious indicators and data associated with the malicious indicators, such as indicator attributes, including time of threats, types of threats, confidence of the threats being valid (i.e., confidence score), severity of the threats, destination and source ports,” destination and source ports are considered when correlating logs to the threat data store.)
occurring within a timeframe between the timestamped message reported by the cybersecurity sensory agent monitoring the device (Huang: para.0085 “The processor determines 904 an exposed set of host identifiers based on the mapped flow of network traffic mapped at step 903. The processor determines the exposed set of host identifiers by determining host nodes having inbound traffic from at least one indicator node. The exposed set of host identifiers identifies hosts that form an attack surface of the client domain 110.” Para.0030 “, the external network 230 may be a public network, such as the internet.” Para.0020 “As used herein an “asset,” may refer to a physical or virtual device that can send and receive data. For example, an asset may be a client or a server that sends and receives applications, services, other data, or some combination thereof. A “network host,” “host,” or “host asset” may refer to an asset that communicates with other assets through a particular network or domain (i.e., communicates with other hosts of the domain).” Devices, i.e. the devices associated with the identified hosts, exposed to the public internet are identified via the domain scan as in para.0082 Fig. 9 902-905. These devices that are exposed to the public internet are within the timeframe of obtaining of the network logs and domain scan, as after the network logs are obtained, i.e. connection notification, as the domain scan is performed to determine matches. Therefore during the time of the domain scan, after obtaining the connection notification but before completion of the domain scan, matches are determined.)
and a timestamped domain scan of IP addresses (Huang: Para.0051 “ For example, log-threat correlation module 202 scans a list of malicious indicators in threat data store 212 and compares each entry to each network log in the network traffic log store 210 that is associated with the client domain 110. If there is a match between a malicious indicator from threat data store 212 and an identifier found in a network traffic log for client domain 110 (e.g., matching IP address, domain name, or other unique identifier or network address), then the identifier found in the network traffic log is determined to be a malicious indicator.” Para.0048 “Threat data store 212 stores data for identifying threats. The data may include “threat data feeds.” A used herein, a “threat data feed” may refer to a set of data corresponding to threats, including lists of malicious indicators and data associated with the malicious indicators, such as indicator attributes, including time of threats” ip address matches are performed with a scan of the threat data store, which is timestamped. This match occurs within a timeframe of the message being reported and the scan, as the match would have to occur after the message is reported and during the scan.)
associated with a domain name (Huang: Para.0051 “ If there is a match between a malicious indicator from threat data store 212 and an identifier found in a network traffic log for client domain 110 (e.g., matching IP address, domain name, or other unique identifier or network address), then the identifier found in the network traffic log is determined to be a malicious indicator.” The network traffics logs associated with the domain are then compared to domain information from a threat indicator data store to determine matching addresses and domain names.); and
in response to the IP address match and the port match occurring within the timeframe between the timestamped message and the timestamped domain scan of the IP addresses associated with the domain name, identifying the device as the exposed to the public Internet (Huang: para.0085 “The processor determines 904 an exposed set of host identifiers based on the mapped flow of network traffic mapped at step 903. The processor determines the exposed set of host identifiers by determining host nodes having inbound traffic from at least one indicator node. The exposed set of host identifiers identifies hosts that form an attack surface of the client domain 110.” para.0028 “ Furthermore, the system determines which ports of the hosts may be exposed (e.g., to the internet) on these assets.” Para.0020 “As used herein an “asset,” may refer to a physical or virtual device that can send and receive data. For example, an asset may be a client or a server that sends and receives applications, services, other data, or some combination thereof. A “network host,” “host,” or “host asset” may refer to an asset that communicates with other assets through a particular network or domain (i.e., communicates with other hosts of the domain).” Devices, i.e. the devices associated with the identified hosts, exposed to the public internet are identified via the domain scan as in para.0082 Fig. 9 902-905. These devices are exposed to the public internet between the time frame of obtaining of the network logs and the scan of network addresses, as the scan itself it a process in which matches of the identifiers, such as addresses, are determined).
However Huang does not explicitly disclose SYN-ACK message, being in the network logs.
Ahn discloses a SYN-ACK message (Ahn: para.0024 “timestamp” para.0030 “Proxy device 112 may utilize the parameters to generate packets comprising data configured to establish a connection between proxy device 112 and host 106 (e.g., a TCP: SYN-ACK handshake message) and, at step #12, may communicate the packets to host 106. Rules 212 may be configured to cause rule gate 120 to one or more of identify the packets, determine (e.g., based on one or more network addresses included in their network-layer headers) that the packets comprise data corresponding to the network-threat indicators, for example, by correlating the packets with one or more of the packets comprising the DNS query or the reply to the DNS query based on data stored in logs 214 (e.g., the log data generated by rule gate 126 in one or more of steps # 6 or #7), and one or more of log or drop the packets.” Para.0020 “The threat-intelligence reports may include one or more network-threat indicators, for example, domain names (e.g., fully qualified domain names (FQDNs)), URIs, network addresses, or the like.” SYN-ACK packets are intercepted and checked for network threat indicators such as network address matches.)
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Huang with Ahn in order to incorporate a SYN-ACK message, and apply this concept to Huang such that SYN-ACK messages are considered in the network logs for identifying exposed assets.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved security (Ahn: para.0002).
Regarding Claim 11, Huang discloses claim 8 as set forth above.
Huang further discloses wherein the operations further comprise determining the port match based on a source port specified by both the timestamped message and the timestamped domain scan of the IP addresses associated with the domain name (Huang: para.0028 “ Furthermore, the system determines which ports of the hosts may be exposed (e.g., to the internet) on these assets.” Para.0048 “Threat data store 212 stores data for identifying threats. The data may include “threat data feeds.” A used herein, a “threat data feed” may refer to a set of data corresponding to threats, including lists of malicious indicators and data associated with the malicious indicators, such as … destination and source ports,” para.0051 “For example, log-threat correlation module 202 scans a list of malicious indicators in threat data store 212 and compares each entry to each network log in the network traffic log store 210 that is associated with the client domain 110. If there is a match between a malicious indicator from threat data store 212 and an identifier found in a network traffic log for client domain 110 (e.g., matching IP address, domain name, or other unique identifier or network address), then the identifier found in the network traffic log is determined to be a malicious indicator.” Para.0083 “The processor correlates 902 the network traffic logs to threat data. The processor correlates the network traffic logs 220A with threat data feeds from threat data store 212 to identify malicious indicators and to identify host identifiers communicating with the malicious indicators in the network traffic logs 220A. The identified host identifiers identify the hosts of the client domain 110.” para.0047 “ The network traffic logs may comprise timestamps indicating times when each message in a network traffic log was transmitted and received” Para.0048 “Threat data store 212 stores …, including time of threats” Based on matching source and destination ports from the logs to the threat data store, assets that are internet facing may be identified.).
However Huang does not explicitly disclose SYN-ACK message.
Ahn discloses a SYN-ACK message (Ahn: para.0024 “timestamp” para.0030 “Proxy device 112 may utilize the parameters to generate packets comprising data configured to establish a connection between proxy device 112 and host 106 (e.g., a TCP: SYN-ACK handshake message) and, at step #12, may communicate the packets to host 106. Rules 212 may be configured to cause rule gate 120 to one or more of identify the packets, determine (e.g., based on one or more network addresses included in their network-layer headers) that the packets comprise data corresponding to the network-threat indicators, for example, by correlating the packets with one or more of the packets comprising the DNS query or the reply to the DNS query based on data stored in logs 214 (e.g., the log data generated by rule gate 126 in one or more of steps # 6 or #7), and one or more of log or drop the packets.” Para.0020 “The threat-intelligence reports may include one or more network-threat indicators, for example, domain names (e.g., fully qualified domain names (FQDNs)), URIs, network addresses, or the like.” SYN-ACK packets are intercepted and checked for network threat indicators such as network address matches.)
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Huang with Ahn in order to incorporate a SYN-ACK message, and apply this concept to Huang such that SYN-ACK messages are considered in the network logs for identifying exposed assets.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved security (Ahn: para.0002).
Regarding Claim 12, Huang discloses claim 8 as set forth above.
Huang further discloses wherein the operations further comprise determining the port match based on a destination port specified by both the timestamped message and the timestamped domain scan of the IP addresses associated with the domain name (Huang: para.0028 “ Furthermore, the system determines which ports of the hosts may be exposed (e.g., to the internet) on these assets.” Para.0048 “Threat data store 212 stores data for identifying threats. The data may include “threat data feeds.” A used herein, a “threat data feed” may refer to a set of data corresponding to threats, including lists of malicious indicators and data associated with the malicious indicators, such as … destination and source ports,” para.0051 “For example, log-threat correlation module 202 scans a list of malicious indicators in threat data store 212 and compares each entry to each network log in the network traffic log store 210 that is associated with the client domain 110. If there is a match between a malicious indicator from threat data store 212 and an identifier found in a network traffic log for client domain 110 (e.g., matching IP address, domain name, or other unique identifier or network address), then the identifier found in the network traffic log is determined to be a malicious indicator.” Para.0083 “The processor correlates 902 the network traffic logs to threat data. The processor correlates the network traffic logs 220A with threat data feeds from threat data store 212 to identify malicious indicators and to identify host identifiers communicating with the malicious indicators in the network traffic logs 220A. The identified host identifiers identify the hosts of the client domain 110.” para.0047 “ The network traffic logs may comprise timestamps indicating times when each message in a network traffic log was transmitted and received” Para.0048 “Threat data store 212 stores …, including time of threats” Based on matching source and destination ports from the logs to the threat data store during the domain scan, i.e. the threat database may be scanned for matching domains to the connection notification, assets that are internet facing may be identified.).
However Huang does not explicitly disclose SYN-ACK message.
Ahn discloses a SYN-ACK message (Ahn: para.0024 “timestamp” para.0030 “Proxy device 112 may utilize the parameters to generate packets comprising data configured to establish a connection between proxy device 112 and host 106 (e.g., a TCP: SYN-ACK handshake message) and, at step #12, may communicate the packets to host 106. Rules 212 may be configured to cause rule gate 120 to one or more of identify the packets, determine (e.g., based on one or more network addresses included in their network-layer headers) that the packets comprise data corresponding to the network-threat indicators, for example, by correlating the packets with one or more of the packets comprising the DNS query or the reply to the DNS query based on data stored in logs 214 (e.g., the log data generated by rule gate 126 in one or more of steps # 6 or #7), and one or more of log or drop the packets.” Para.0020 “The threat-intelligence reports may include one or more network-threat indicators, for example, domain names (e.g., fully qualified domain names (FQDNs)), URIs, network addresses, or the like.” SYN-ACK packets are intercepted and checked for network threat indicators such as network address matches.)
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Huang with Ahn in order to incorporate a SYN-ACK message, and apply this concept to Huang such that SYN-ACK messages are considered in the network logs for identifying exposed assets.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved security (Ahn: para.0002).
Regarding Claim 14, Huang discloses claim 8 as set forth above.
Huang further discloses wherein the operations further comprise determining a public network address and a port associated with the device identified as the exposed to the public Internet (Huang: para.0019 “As such, the attack surface may comprise identifiers for each entry point, such as host identifiers (hosts IDs), port identifiers, device identifiers, combinations thereof, and the like.” para.0074 “ The dashboard may provide contents generated from prioritized attack surface data structure 221A. Entries of a report (e.g., report 401 or report 402), such as entries with private IP addresses, may be investigated using dashboard 403. Inbound traffic may not be expected to private IP addresses, which if detected, may indicate that a firewall is misconfigured and allowing traffic from a known indicator of compromise. A user of user device 240 (e.g., an analyst) can gain further insight into this host using dashboard 403, as shown in the following example. The event data about hosts 10.244.74.35 and 10.256.255.12 is automatically correlated with threat intelligence and asset enrichment.” Para.0028 “Furthermore, the system determines which ports of the hosts may be exposed (e.g., to the internet) on these assets.” The address and ports of the exposed hosts are identified.).
Claim(s) 2, 3, 9, 10 15-18, 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Huang et al. (hereinafter Huang US 2023/0344848 A1) in view of Ahn et al. (hereinafter Ahn, US 2022/0014538 A1) in view of Cross et al. (hereinafter Cross, US 11,720,686 B1).
Regarding Claim 2, Huang-Ahn discloses Claim 1 as set forth above.
Huang further discloses wherein the identifying of the device as the exposed to the public Internet further comprises determining a network address specified by both the timestamped message and the timestamped scan of the IP addresses associated with the public Internet (Huang: para.0028 “ Furthermore, the system determines which ports of the hosts may be exposed (e.g., to the internet) on these assets.” para.0051 “For example, log-threat correlation module 202 scans a list of malicious indicators in threat data store 212 and compares each entry to each network log in the network traffic log store 210 that is associated with the client domain 110. If there is a match between a malicious indicator from threat data store 212 and an identifier found in a network traffic log for client domain 110 (e.g., matching IP address, domain name, or other unique identifier or network address), then the identifier found in the network traffic log is determined to be a malicious indicator.” Para.0083 “The processor correlates 902 the network traffic logs to threat data. The processor correlates the network traffic logs 220A with threat data feeds from threat data store 212 to identify malicious indicators and to identify host identifiers communicating with the malicious indicators in the network traffic logs 220A. The identified host identifiers identify the hosts of the client domain 110.” para.0047 “ The network traffic logs may comprise timestamps indicating times when each message in a network traffic log was transmitted and received” Para.0048 “Threat data store 212 stores …, including time of threats” Based on matching addresses from the logs to the threat data store, assets that are internet facing may be identified.).
However while discloses matching addresses in general, Huang does not explicitly disclose wherein the identifying of the device as the exposed to the public Internet further comprises determining a source network address specified by both the timestamped SYN-ACK message and the timestamped scan of the IP addresses associated with the public Internet.
Ahn discloses a SYN-ACK message (Ahn: para.0024 “timestamp” para.0030 “Proxy device 112 may utilize the parameters to generate packets comprising data configured to establish a connection between proxy device 112 and host 106 (e.g., a TCP: SYN-ACK handshake message) and, at step #12, may communicate the packets to host 106. Rules 212 may be configured to cause rule gate 120 to one or more of identify the packets, determine (e.g., based on one or more network addresses included in their network-layer headers) that the packets comprise data corresponding to the network-threat indicators, for example, by correlating the packets with one or more of the packets comprising the DNS query or the reply to the DNS query based on data stored in logs 214 (e.g., the log data generated by rule gate 126 in one or more of steps # 6 or #7), and one or more of log or drop the packets.” Para.0020 “The threat-intelligence reports may include one or more network-threat indicators, for example, domain names (e.g., fully qualified domain names (FQDNs)), URIs, network addresses, or the like.” SYN-ACK packets are intercepted and checked for network threat indicators such as network address matches.)
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Huang with Ahn in order to incorporate a SYN-ACK message, and apply this concept to Huang such that SYN-ACK messages are considered in the network logs for identifying exposed assets.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved security (Ahn: para.0002).
However while discloses matching addresses in general, Huang does not explicitly disclose wherein the identifying of the device as the exposed to the public Internet further comprises determining a source network address specified by both the timestamped SYN-ACK message and the timestamped scan of the IP addresses associated with the public Internet.
Cross discloses wherein the identifying of the device as the exposed to the public Internet (Cross: col. 31 lines 1-8 “. Advantageously, in the event the perimeter of the system needs to be secured such that Internet communications are undesirable, a scanless operation can help identify vulnerabilities without gaining system exposure to external entities.” In col. 61 line 60-col. 62 line 24, Cross initially obtains internet connected devices, and identifies vulnerabilities of those devices in step 1806 of Fig. 18) further comprises determining a source network address specified by both the message and the scan of the IP addresses associated with the public Internet (Cross: col. 61 line 60-col. 62 line 24 “The method 1800 begins at process 1802 with the remediation manager 1714 of the remediation system 114 receiving device connectivity data (e.g., as discussed above, with reference to FIGS. 1-11) for an entity (e.g., vendor). The device connectivity data can be received from a search and discovery engine for internet-connected devices, such as Shodan. … The properties can include device-related data and/or IP traffic data. … Device-related data can include IP address(es),… port number(s), timestamp data, host name, etc. IP traffic data can include items included in packets, as described elsewhere herein..” col. 11 line 20-39 “ For example, in addition to a payload, application-layer and/or link-layer in an example packet, may contain a header and/or footer that may include a source address of the sending host (e.g., a user device)” col. 62 lines 25-52 “At process 1806, the remediation manager 1714 identifies a vulnerability associated with a particular property. …For example, for each property in the collection of properties parsed from the device connectivity data, the remediation system 114 may reference the remediation executable vault 1704. If the property is found in the remediation executable vault 1704 previously populated with external data from NVD or a similar entity, the remediation manager determines 1714 determines that the property is associated with a vulnerability.” the remediation system of Fig. 1 in the cyber security assurance system, the external attack surface management system, receives connectivity data including packets comprising headers and source addresses, and compared them in steps 1804-1806 to identify vulnerabilities in the network).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date to combine Huang-Ahn with Cross in order to incorporate wherein the identifying of the device as the exposed to the public Internet further comprises determining a source network address specified by both the timestamped message and the timestamped scan of the network addresses associated with the public Internet, and apply this concept to the timestamped SYN-ACK message and the timestamped domain scan of Huang-Ahn.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved cybersecurity by detecting and addressing cyber security vulnerabilities (Cross: col. 4 lines 4-47).
Regarding Claim 3, Huang-Ahn teaches claim 1 as set forth above.
Huang further discloses wherein the identifying of the device as the exposed to the public Internet further comprises determining a network address specified by both the timestamped message and the timestamped scan of the IP addresses associated with the public Internet (Huang: para.0028 “ Furthermore, the system determines which ports of the hosts may be exposed (e.g., to the internet) on these assets.” para.0051 “For example, log-threat correlation module 202 scans a list of malicious indicators in threat data store 212 and compares each entry to each network log in the network traffic log store 210 that is associated with the client domain 110. If there is a match between a malicious indicator from threat data store 212 and an identifier found in a network traffic log for client domain 110 (e.g., matching IP address, domain name, or other unique identifier or network address), then the identifier found in the network traffic log is determined to be a malicious indicator.” Para.0083 “The processor correlates 902 the network traffic logs to threat data. The processor correlates the network traffic logs 220A with threat data feeds from threat data store 212 to identify malicious indicators and to identify host identifiers communicating with the malicious indicators in the network traffic logs 220A. The identified host identifiers identify the hosts of the client domain 110.” para.0047 “ The network traffic logs may comprise timestamps indicating times when each message in a network traffic log was transmitted and received” Para.0048 “Threat data store 212 stores …, including time of threats” Based on matching addresses from the logs to the threat data store, assets that are internet facing may be identified.).
However Huang does not explicitly disclose wherein the identifying of the device as the exposed to the public Internet further comprises determining a destination network address specified by both the timestamped SYN-ACK message and the timestamped scan of the IP addresses associated with the public Internet.
Ahn discloses a SYN-ACK message (Ahn: para.0024 “timestamp” para.0030 “Proxy device 112 may utilize the parameters to generate packets comprising data configured to establish a connection between proxy device 112 and host 106 (e.g., a TCP: SYN-ACK handshake message) and, at step #12, may communicate the packets to host 106. Rules 212 may be configured to cause rule gate 120 to one or more of identify the packets, determine (e.g., based on one or more network addresses included in their network-layer headers) that the packets comprise data corresponding to the network-threat indicators, for example, by correlating the packets with one or more of the packets comprising the DNS query or the reply to the DNS query based on data stored in logs 214 (e.g., the log data generated by rule gate 126 in one or more of steps # 6 or #7), and one or more of log or drop the packets.” Para.0020 “The threat-intelligence reports may include one or more network-threat indicators, for example, domain names (e.g., fully qualified domain names (FQDNs)), URIs, network addresses, or the like.” SYN-ACK packets are intercepted and checked for network threat indicators such as network address matches.)
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Huang with Ahn in order to incorporate a SYN-ACK message, and apply this concept to Huang such that SYN-ACK messages are considered in the network logs for identifying exposed assets.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved security (Ahn: para.0002).
However Huang-Ahn does not explicitly disclose wherein the identifying of the device as the exposed to the public Internet further comprises determining a destination network address specified by both the timestamped SYN-ACK message and the timestamped scan of the IP addresses associated with the public Internet.
Cross discloses wherein the identifying of the device as the exposed to the public Internet (Cross: col. 31 lines 1-8 “. Advantageously, in the event the perimeter of the system needs to be secured such that Internet communications are undesirable, a scanless operation can help identify vulnerabilities without gaining system exposure to external entities.” In col. 61 line 60-col. 62 line 24, Cross initially obtains internet connected devices, and identifies vulnerabilities of those devices in step 1806 of Fig. 18) further comprises determining a destination network address specified by both the message and the scan of the IP addresses associated with the public Internet (Cross: col. 61 line 60-col. 62 line 24 “The method 1800 begins at process 1802 with the remediation manager 1714 of the remediation system 114 receiving device connectivity data (e.g., as discussed above, with reference to FIGS. 1-11) for an entity (e.g., vendor). The device connectivity data can be received from a search and discovery engine for internet-connected devices, such as Shodan. … The properties can include device-related data and/or IP traffic data. … Device-related data can include IP address(es),… port number(s), timestamp data, host name, etc. IP traffic data can include items included in packets, as described elsewhere herein..” col. 11 line 20-39 “ For example, in addition to a payload, application-layer and/or link-layer in an example packet, may contain a header and/or footer that may include a source address of the sending host (e.g., a user device), destination address of the target host, a source port, a destination port” col. 62 lines 25-52 “At process 1806, the remediation manager 1714 identifies a vulnerability associated with a particular property. …For example, for each property in the collection of properties parsed from the device connectivity data, the remediation system 114 may reference the remediation executable vault 1704. If the property is found in the remediation executable vault 1704 previously populated with external data from NVD or a similar entity, the remediation manager determines 1714 determines that the property is associated with a vulnerability.” the remediation system of Fig. 1 in the cyber security assurance system, the external attack surface management system, receives connectivity data including packets comprising headers and destination addresses, and compared them in steps 1804-1806 to identify vulnerabilities in the network).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date to combine Huang-Ahn with Cross in order to incorporate wherein the identifying of the device as the exposed to the public Internet further comprises determining a destination network address specified by both the timestamped message and the scan of the IP addresses associated with the public Internet, and apply this concept to the timestamped SYN-ACK message and the timestamped domain scan of Huang-Ahn.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved cybersecurity by detecting and addressing cyber security vulnerabilities (Cross: col. 4 lines 4-47).
Regarding Claim 9, Huang-Ahn teaches claim 8 as set forth above.
Huang further discloses wherein the operations further comprise determining the IP address match based on a network address specified by both the timestamped message and the timestamped domain scan of the IP addresses associated with the domain name (Huang: para.0028 “ Furthermore, the system determines which ports of the hosts may be exposed (e.g., to the internet) on these assets.” para.0051 “For example, log-threat correlation module 202 scans a list of malicious indicators in threat data store 212 and compares each entry to each network log in the network traffic log store 210 that is associated with the client domain 110. If there is a match between a malicious indicator from threat data store 212 and an identifier found in a network traffic log for client domain 110 (e.g., matching IP address, domain name, or other unique identifier or network address), then the identifier found in the network traffic log is determined to be a malicious indicator.” Para.0083 “The processor correlates 902 the network traffic logs to threat data. The processor correlates the network traffic logs 220A with threat data feeds from threat data store 212 to identify malicious indicators and to identify host identifiers communicating with the malicious indicators in the network traffic logs 220A. The identified host identifiers identify the hosts of the client domain 110.” para.0047 “ The network traffic logs may comprise timestamps indicating times when each message in a network traffic log was transmitted and received” Para.0048 “Threat data store 212 stores …, including time of threats” Based on matching addresses from the logs to the threat data store, assets that are internet facing may be identified.).
However while discloses matching addresses in general, Huang does not explicitly disclose wherein the operations further comprise determining the IP address match based on a source network address specified by both the timestamped SYN-ACK message and the timestamped domain scan of the IP addresses associated with the domain name.
Ahn discloses a SYN-ACK message (Ahn: para.0024 “timestamp” para.0030 “Proxy device 112 may utilize the parameters to generate packets comprising data configured to establish a connection between proxy device 112 and host 106 (e.g., a TCP: SYN-ACK handshake message) and, at step #12, may communicate the packets to host 106. Rules 212 may be configured to cause rule gate 120 to one or more of identify the packets, determine (e.g., based on one or more network addresses included in their network-layer headers) that the packets comprise data corresponding to the network-threat indicators, for example, by correlating the packets with one or more of the packets comprising the DNS query or the reply to the DNS query based on data stored in logs 214 (e.g., the log data generated by rule gate 126 in one or more of steps # 6 or #7), and one or more of log or drop the packets.” Para.0020 “The threat-intelligence reports may include one or more network-threat indicators, for example, domain names (e.g., fully qualified domain names (FQDNs)), URIs, network addresses, or the like.” SYN-ACK packets are intercepted and checked for network threat indicators such as network address matches.)
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Huang with Ahn in order to incorporate a SYN-ACK message, and apply this concept to Huang such that SYN-ACK messages are considered in the network logs for identifying exposed assets.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved security (Ahn: para.0002).
However Huang-Ahn does not explicitly disclose wherein the operations further comprise determining the IP address match based on a source network address specified by both the timestamped SYN-ACK message and the timestamped domain scan of the IP addresses associated with the domain name.
Cross discloses determining the IP address match based on a source network address specified by both the timestamped message and the domain scan of the IP addresses associated with the domain name (Cross: col. 61 line 60-col. 62 line 24 “The method 1800 begins at process 1802 with the remediation manager 1714 of the remediation system 114 receiving device connectivity data (e.g., as discussed above, with reference to FIGS. 1-11) for an entity (e.g., vendor). The device connectivity data can be received from a search and discovery engine for internet-connected devices, such as Shodan. … The properties can include device-related data and/or IP traffic data. … Device-related data can include IP address(es),… port number(s), timestamp data, host name, etc. IP traffic data can include items included in packets, as described elsewhere herein..” col. 11 line 20-39 “ For example, in addition to a payload, application-layer and/or link-layer in an example packet, may contain a header and/or footer that may include a source address of the sending host (e.g., a user device)” col. 62 lines 25-52 “At process 1806, the remediation manager 1714 identifies a vulnerability associated with a particular property. …For example, for each property in the collection of properties parsed from the device connectivity data, the remediation system 114 may reference the remediation executable vault 1704. If the property is found in the remediation executable vault 1704 previously populated with external data from NVD or a similar entity, the remediation manager determines 1714 determines that the property is associated with a vulnerability.” the remediation system of Fig. 1 in the cyber security assurance system, the external attack surface management system, receives connectivity data including packets comprising headers and source addresses, and compared them in steps 1804-1806 to identify vulnerabilities in the network).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date to combine Huang-Ahn with Cross in order to incorporate determining the IP address match based on a source network address specified by both the timestamped message and the domain scan of the IP addresses associated with the domain name, and apply this concept to the timestamped SYN-ACK message and the timestamped domain scan of Huang-Ahn.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved cybersecurity by detecting and addressing cyber security vulnerabilities (Cross: col. 4 lines 4-47).
Regarding Claim 10, Huang discloses claim 8 as set forth above.
Huang further discloses wherein the operations further comprise determining the IP address match based on a network address specified by both the timestamped message and the timestamped domain scan of the IP addresses associated with the domain name(Huang: para.0028 “ Furthermore, the system determines which ports of the hosts may be exposed (e.g., to the internet) on these assets.” para.0051 “For example, log-threat correlation module 202 scans a list of malicious indicators in threat data store 212 and compares each entry to each network log in the network traffic log store 210 that is associated with the client domain 110. If there is a match between a malicious indicator from threat data store 212 and an identifier found in a network traffic log for client domain 110 (e.g., matching IP address, domain name, or other unique identifier or network address), then the identifier found in the network traffic log is determined to be a malicious indicator.” Para.0083 “The processor correlates 902 the network traffic logs to threat data. The processor correlates the network traffic logs 220A with threat data feeds from threat data store 212 to identify malicious indicators and to identify host identifiers communicating with the malicious indicators in the network traffic logs 220A. The identified host identifiers identify the hosts of the client domain 110.” para.0047 “ The network traffic logs may comprise timestamps indicating times when each message in a network traffic log was transmitted and received” Para.0048 “Threat data store 212 stores …, including time of threats” Based on matching addresses from the logs to the threat data store, assets that are internet facing may be identified.).
However Huang does not explicitly disclose wherein the operations further comprise determining the IP address match based on a destination network address specified by both the timestamped SYN-ACK message and the timestamped domain scan of the IP addresses associated with the domain name.
Ahn discloses a SYN-ACK message (Ahn: para.0024 “timestamp” para.0030 “Proxy device 112 may utilize the parameters to generate packets comprising data configured to establish a connection between proxy device 112 and host 106 (e.g., a TCP: SYN-ACK handshake message) and, at step #12, may communicate the packets to host 106. Rules 212 may be configured to cause rule gate 120 to one or more of identify the packets, determine (e.g., based on one or more network addresses included in their network-layer headers) that the packets comprise data corresponding to the network-threat indicators, for example, by correlating the packets with one or more of the packets comprising the DNS query or the reply to the DNS query based on data stored in logs 214 (e.g., the log data generated by rule gate 126 in one or more of steps # 6 or #7), and one or more of log or drop the packets.” Para.0020 “The threat-intelligence reports may include one or more network-threat indicators, for example, domain names (e.g., fully qualified domain names (FQDNs)), URIs, network addresses, or the like.” SYN-ACK packets are intercepted and checked for network threat indicators such as network address matches.)
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Huang with Ahn in order to incorporate a SYN-ACK message, and apply this concept to Huang such that SYN-ACK messages are considered in the network logs for identifying exposed assets.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved security (Ahn: para.0002).
However Huang-Ahn does not explicitly disclose wherein the operations further comprise determining the IP address match based on a destination network address specified by both the timestamped SYN-ACK message and the timestamped domain scan of the IP addresses associated with the domain name.
Cross discloses wherein the operations further comprise determining the IP address match based on a destination network address specified by both the message and the domain scan of the IP addresses associated with the domain name (Cross: col. 61 line 60-col. 62 line 24 “The method 1800 begins at process 1802 with the remediation manager 1714 of the remediation system 114 receiving device connectivity data (e.g., as discussed above, with reference to FIGS. 1-11) for an entity (e.g., vendor). The device connectivity data can be received from a search and discovery engine for internet-connected devices, such as Shodan. … The properties can include device-related data and/or IP traffic data. … Device-related data can include IP address(es),… port number(s), timestamp data, host name, etc. IP traffic data can include items included in packets, as described elsewhere herein..” col. 11 line 20-39 “ For example, in addition to a payload, application-layer and/or link-layer in an example packet, may contain a header and/or footer that may include a source address of the sending host (e.g., a user device), destination address of the target host, a source port, a destination port” col. 62 lines 25-52 “At process 1806, the remediation manager 1714 identifies a vulnerability associated with a particular property. …For example, for each property in the collection of properties parsed from the device connectivity data, the remediation system 114 may reference the remediation executable vault 1704. If the property is found in the remediation executable vault 1704 previously populated with external data from NVD or a similar entity, the remediation manager determines 1714 determines that the property is associated with a vulnerability.” the remediation system of Fig. 1 in the cyber security assurance system, the external attack surface management system, receives connectivity data including packets comprising headers and destination addresses, and compared them in steps 1804-1806 to identify vulnerabilities in the network).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date to combine Huang with Cross in order to incorporate wherein the operations further comprise determining the IP address match based on a destination network address specified by both the message and the domain scan of the IP addresses associated with the domain name, and apply this concept to the timestamped SYN-ACK message and the timestamped domain scan of Huang-Ahn.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved cybersecurity by detecting and addressing cyber security vulnerabilities (Cross: col. 4 lines 4-47).
Regarding Claim 15, Huang discloses A memory device storing instructions that, when executed by a central processing unit (Huang: Fig. 2 Computing system 220, para.0046 “Attack surface management engine 221 may comprise modules of computer-executable instructions, or code, for performing functional tasks when executed by a processor.” Computing system 220 comprising attack surface management engine executing instructions by a processor.), perform operations, comprising:
receiving a timestamped message reported by a cybersecurity sensory agent monitoring a device (Huang: para.0095 “The one or more processors may also operate to support performance of the relevant operations in a “cloud computing” environment or as a “software as a service” (SaaS).” In a cloud computing environment.) to an external attack surface management service (Huang: para.0082 “The processor obtains 901 network traffic logs for a client domain 110. In one embodiment a user of user device 240 may provide (e.g., upload) the network traffic logs 220A for the client domain 110 to the computing system 220, or to a database 250 accessible by the computing system 220, via external network 230. In another embodiment, computing system 220 may actively monitor the network traffic of client domain 110 to obtain the network traffic logs 220A.” a connection notification, the network traffic logs, are reported by the user device 240, the software of user device 240 being the cybersecurity sensory agent. The attack surface management engine, para.0032, obtains this information from the user device 240.);
reading a message information specifying a source network address captured by the cybersecurity sensory agent (Huang: para.0082 “The processor obtains 901 network traffic logs for a client domain 110.” Para.0083 “The processor correlates 902 the network traffic logs to threat data. The processor correlates the network traffic logs 220A with threat data feeds from threat data store 212 to identify malicious indicators and to identify host identifiers communicating with the malicious indicators in the network traffic logs 220A. The identified host identifiers identify the hosts of the client domain 110.” Para.0051 “For example, if a particular IP address, domain name, or other network address is attempting to communicate with several hosts/identifiers from the network traffic logs 220A over a short period of time or is engaging in other anomalous network behavior, as reflected in the network traffic logs 220A, then the particular network address may be identified as a malicious indicator for the client domain 110.” The traffic logs are read to obtain address information, such as a source ip address of communication);
determining a port match (Huang: para.0028 “ Furthermore, the system determines which ports of the hosts may be exposed (e.g., to the internet) on these assets.” Para.0054 “For example, attribute determination module 205 may retrieve attributes associated with each host identifier in the exposed set from database 250, such as services associated with ports of the host identifier, a criticality level associated with the host identifier (e.g., as designated by an admin of the client domain 110), vulnerabilities associated with the host identifier, level of criticality associated with the vulnerabilities, other host attributes for generating values of a feature vector for the host identifier, or some combination thereof.” Para.0048 “including lists of malicious indicators and data associated with the malicious indicators, such as indicator attributes, including time of threats, types of threats, confidence of the threats being valid (i.e., confidence score), severity of the threats, destination and source ports,” destination and source ports are considered when correlating logs to the threat data store.)
occurring within a timeframe between the timestamped SYN-ACK message reported by the cybersecurity sensory agent (Huang: para.0085 “The processor determines 904 an exposed set of host identifiers based on the mapped flow of network traffic mapped at step 903. The processor determines the exposed set of host identifiers by determining host nodes having inbound traffic from at least one indicator node. The exposed set of host identifiers identifies hosts that form an attack surface of the client domain 110.” Para.0030 “, the external network 230 may be a public network, such as the internet.” Para.0020 “As used herein an “asset,” may refer to a physical or virtual device that can send and receive data. For example, an asset may be a client or a server that sends and receives applications, services, other data, or some combination thereof. A “network host,” “host,” or “host asset” may refer to an asset that communicates with other assets through a particular network or domain (i.e., communicates with other hosts of the domain).” Devices, i.e. the devices associated with the identified hosts, exposed to the public internet are identified via the domain scan as in para.0082 Fig. 9 902-905. These devices that are exposed to the public internet are within the timeframe of obtaining of the network logs and domain scan, as after the network logs are obtained, i.e. connection notification, as the domain scan is performed to determine matches. Therefore during the time of the domain scan, after obtaining the connection notification but before completion of the domain scan, matches are determined.)
and a timestamped domain scan of Internet Protocol (IP) addresses associated with a domain name (Huang: Para.0051 “ For example, log-threat correlation module 202 scans a list of malicious indicators in threat data store 212 and compares each entry to each network log in the network traffic log store 210 that is associated with the client domain 110. If there is a match between a malicious indicator from threat data store 212 and an identifier found in a network traffic log for client domain 110 (e.g., matching IP address, domain name, or other unique identifier or network address), then the identifier found in the network traffic log is determined to be a malicious indicator.” Para.0048 “Threat data store 212 stores data for identifying threats. The data may include “threat data feeds.” A used herein, a “threat data feed” may refer to a set of data corresponding to threats, including lists of malicious indicators and data associated with the malicious indicators, such as indicator attributes, including time of threats” ip address matches are performed with a scan of the threat data store, which is timestamped. This match occurs within a timeframe of the message being reported and the scan, as the match would have to occur after the message is reported and during the scan.); and
in response to the port match occurring within the timeframe between the timestamped message reported by the cybersecurity sensory agent and the timestamped domain scan of the IP addresses associated with the domain name, identifying the device as exposed to a public Internet (Huang: para.0085 “The processor determines 904 an exposed set of host identifiers based on the mapped flow of network traffic mapped at step 903. The processor determines the exposed set of host identifiers by determining host nodes having inbound traffic from at least one indicator node. The exposed set of host identifiers identifies hosts that form an attack surface of the client domain 110.” para.0028 “ Furthermore, the system determines which ports of the hosts may be exposed (e.g., to the internet) on these assets.” Para.0020 “As used herein an “asset,” may refer to a physical or virtual device that can send and receive data. For example, an asset may be a client or a server that sends and receives applications, services, other data, or some combination thereof. A “network host,” “host,” or “host asset” may refer to an asset that communicates with other assets through a particular network or domain (i.e., communicates with other hosts of the domain).” Devices, i.e. the devices associated with the identified hosts, exposed to the public internet are identified via the domain scan as in para.0082 Fig. 9 902-905. These devices are exposed to the public internet between the time frame of obtaining of the network logs and the scan of network addresses, as the scan itself it a process in which matches of the identifiers, such as addresses, are determined)
However Huang does not explicitly disclose SYN-ACK message; reading a packet header specifying a source network address captured by the cybersecurity sensory agent.
Ahn discloses a SYN-ACK message (Ahn: para.0024 “timestamp” para.0030 “Proxy device 112 may utilize the parameters to generate packets comprising data configured to establish a connection between proxy device 112 and host 106 (e.g., a TCP: SYN-ACK handshake message) and, at step #12, may communicate the packets to host 106. Rules 212 may be configured to cause rule gate 120 to one or more of identify the packets, determine (e.g., based on one or more network addresses included in their network-layer headers) that the packets comprise data corresponding to the network-threat indicators, for example, by correlating the packets with one or more of the packets comprising the DNS query or the reply to the DNS query based on data stored in logs 214 (e.g., the log data generated by rule gate 126 in one or more of steps # 6 or #7), and one or more of log or drop the packets.” Para.0020 “The threat-intelligence reports may include one or more network-threat indicators, for example, domain names (e.g., fully qualified domain names (FQDNs)), URIs, network addresses, or the like.” SYN-ACK packets are intercepted and checked for network threat indicators such as network address matches.)
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Huang with Ahn in order to incorporate a SYN-ACK message, and apply this concept to Huang such that SYN-ACK messages are considered in the network logs for identifying exposed assets.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved security (Ahn: para.0002).
However Huang-Ahn does not explicitly disclose reading a packet header specifying a source network address captured by the cybersecurity sensory agent.
Cross discloses reading a packet header specifying a source network address captured by the cybersecurity sensory agent (Cross: Cross: col. 61 line 60-col. 62 line 24 “The method 1800 begins at process 1802 with the remediation manager 1714 of the remediation system 114 receiving device connectivity data (e.g., as discussed above, with reference to FIGS. 1-11) for an entity (e.g., vendor). The device connectivity data can be received from a search and discovery engine for internet-connected devices, such as Shodan. … The properties can include device-related data and/or IP traffic data. … Device-related data can include IP address(es),… port number(s), timestamp data, host name, etc. IP traffic data can include items included in packets, as described elsewhere herein.” Col. 5 lines 45-55 “For example, the data acquisition engine 180 may provide a single API to access various data generated or routed by devices 140, 150 and 155 and/or by the data sources 160. As described further herein, the devices 140, 150 and 155 may provide device connectivity data, IP traffic data and other system-related data” col. 11 line 20-60 “ For example, in addition to a payload, application-layer and/or link-layer in an example packet, may contain a header and/or footer that may include a source address of the sending host (e.g., a user device)… Accordingly, any suitable packet and/or device connectivity data may be used by the multi-channel cybersecurity assurance system 110 to identify vulnerabilities in the associated systems (e.g., at the source system identified by the packet, at the destination system identified by the packet). For example, a header, a footer, and/or metadata of a packet may include routing information for the packet. As used herein, “routing information” is defined as source and/or destination information.” the remediation system of Fig. 1 in the cyber security assurance system, the external attack surface management system, receives connectivity data including packets comprising header from data acquisition engine 180 in Fig. 1. The headers are read to obtain the source and destination addresses.).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date to combine Huang with Cross in order to incorporate reading a packet header specifying a source network address captured by the cybersecurity sensory agent.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved cybersecurity by detecting and addressing cyber security vulnerabilities (Cross: col. 4 lines 4-47).
Regarding Claim 16, Huang-Ahn-Cross discloses claim 15 as set forth above.
Huang further discloses wherein the operations further comprise determining the port match based on a source port specified by both the timestamped message and the timestamped domain scan of the IP addresses associated with the domain name (Huang: para.0028 “ Furthermore, the system determines which ports of the hosts may be exposed (e.g., to the internet) on these assets.” Para.0048 “Threat data store 212 stores data for identifying threats. The data may include “threat data feeds.” A used herein, a “threat data feed” may refer to a set of data corresponding to threats, including lists of malicious indicators and data associated with the malicious indicators, such as … destination and source ports,” para.0051 “For example, log-threat correlation module 202 scans a list of malicious indicators in threat data store 212 and compares each entry to each network log in the network traffic log store 210 that is associated with the client domain 110. If there is a match between a malicious indicator from threat data store 212 and an identifier found in a network traffic log for client domain 110 (e.g., matching IP address, domain name, or other unique identifier or network address), then the identifier found in the network traffic log is determined to be a malicious indicator.” Para.0083 “The processor correlates 902 the network traffic logs to threat data. The processor correlates the network traffic logs 220A with threat data feeds from threat data store 212 to identify malicious indicators and to identify host identifiers communicating with the malicious indicators in the network traffic logs 220A. The identified host identifiers identify the hosts of the client domain 110.” para.0047 “ The network traffic logs may comprise timestamps indicating times when each message in a network traffic log was transmitted and received” Para.0048 “Threat data store 212 stores …, including time of threats” Based on matching source and destination ports from the logs to the threat data store, assets that are internet facing may be identified.).
However Huang does not explicitly disclose SYN-ACK message.
Ahn discloses a SYN-ACK message (Ahn: para.0024 “timestamp” para.0030 “Proxy device 112 may utilize the parameters to generate packets comprising data configured to establish a connection between proxy device 112 and host 106 (e.g., a TCP: SYN-ACK handshake message) and, at step #12, may communicate the packets to host 106. Rules 212 may be configured to cause rule gate 120 to one or more of identify the packets, determine (e.g., based on one or more network addresses included in their network-layer headers) that the packets comprise data corresponding to the network-threat indicators, for example, by correlating the packets with one or more of the packets comprising the DNS query or the reply to the DNS query based on data stored in logs 214 (e.g., the log data generated by rule gate 126 in one or more of steps # 6 or #7), and one or more of log or drop the packets.” Para.0020 “The threat-intelligence reports may include one or more network-threat indicators, for example, domain names (e.g., fully qualified domain names (FQDNs)), URIs, network addresses, or the like.” SYN-ACK packets are intercepted and checked for network threat indicators such as network address matches.)
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Huang with Ahn in order to incorporate a SYN-ACK message, and apply this concept to Huang such that SYN-ACK messages are considered in the network logs for identifying exposed assets.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved security (Ahn: para.0002).
Regarding Claim 17, Huang-Ahn-Cross discloses claim 15 as set forth above.
Huang further discloses wherein the operations further comprise determining the port match based on a destination port specified by both the timestamped message and the timestamped domain scan of the IP addresses associated with the domain name (Huang: para.0028 “ Furthermore, the system determines which ports of the hosts may be exposed (e.g., to the internet) on these assets.” Para.0048 “Threat data store 212 stores data for identifying threats. The data may include “threat data feeds.” A used herein, a “threat data feed” may refer to a set of data corresponding to threats, including lists of malicious indicators and data associated with the malicious indicators, such as … destination and source ports,” para.0051 “For example, log-threat correlation module 202 scans a list of malicious indicators in threat data store 212 and compares each entry to each network log in the network traffic log store 210 that is associated with the client domain 110. If there is a match between a malicious indicator from threat data store 212 and an identifier found in a network traffic log for client domain 110 (e.g., matching IP address, domain name, or other unique identifier or network address), then the identifier found in the network traffic log is determined to be a malicious indicator.” Para.0083 “The processor correlates 902 the network traffic logs to threat data. The processor correlates the network traffic logs 220A with threat data feeds from threat data store 212 to identify malicious indicators and to identify host identifiers communicating with the malicious indicators in the network traffic logs 220A. The identified host identifiers identify the hosts of the client domain 110.” para.0047 “ The network traffic logs may comprise timestamps indicating times when each message in a network traffic log was transmitted and received” Para.0048 “Threat data store 212 stores …, including time of threats” Based on matching source and destination ports from the logs to the threat data store during the domain scan, i.e. the threat database may be scanned for matching domains to the connection notification, assets that are internet facing may be identified.).
However Huang does not explicitly disclose SYN-ACK message.
Ahn discloses a SYN-ACK message (Ahn: para.0024 “timestamp” para.0030 “Proxy device 112 may utilize the parameters to generate packets comprising data configured to establish a connection between proxy device 112 and host 106 (e.g., a TCP: SYN-ACK handshake message) and, at step #12, may communicate the packets to host 106. Rules 212 may be configured to cause rule gate 120 to one or more of identify the packets, determine (e.g., based on one or more network addresses included in their network-layer headers) that the packets comprise data corresponding to the network-threat indicators, for example, by correlating the packets with one or more of the packets comprising the DNS query or the reply to the DNS query based on data stored in logs 214 (e.g., the log data generated by rule gate 126 in one or more of steps # 6 or #7), and one or more of log or drop the packets.” Para.0020 “The threat-intelligence reports may include one or more network-threat indicators, for example, domain names (e.g., fully qualified domain names (FQDNs)), URIs, network addresses, or the like.” SYN-ACK packets are intercepted and checked for network threat indicators such as network address matches.)
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Huang with Ahn in order to incorporate a SYN-ACK message, and apply this concept to Huang such that SYN-ACK messages are considered in the network logs for identifying exposed assets.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved security (Ahn: para.0002).
Regarding Claim 18, Huang-Ahn-Cross discloses claim 15 as set forth above.
Huang further discloses wherein the operations further comprise determining the network address is matched to both the timestamped message and the timestamped domain scan of the IP addresses associated with the domain name (Huang: para.0028 “ Furthermore, the system determines which ports of the hosts may be exposed (e.g., to the internet) on these assets.” para.0051 “For example, log-threat correlation module 202 scans a list of malicious indicators in threat data store 212 and compares each entry to each network log in the network traffic log store 210 that is associated with the client domain 110. If there is a match between a malicious indicator from threat data store 212 and an identifier found in a network traffic log for client domain 110 (e.g., matching IP address, domain name, or other unique identifier or network address), then the identifier found in the network traffic log is determined to be a malicious indicator.” Para.0083 “The processor correlates 902 the network traffic logs to threat data. The processor correlates the network traffic logs 220A with threat data feeds from threat data store 212 to identify malicious indicators and to identify host identifiers communicating with the malicious indicators in the network traffic logs 220A. The identified host identifiers identify the hosts of the client domain 110.” para.0047 “ The network traffic logs may comprise timestamps indicating times when each message in a network traffic log was transmitted and received” Para.0048 “Threat data store 212 stores …, including time of threats” Based on matching addresses from the logs to the threat data store, assets that are internet facing may be identified.).
However while Huang discloses matching addresses in general, Huang does not explicitly disclose wherein the operations further comprise determining the source network address is matched to both the timestamped SYN-ACK message and the timestamped domain scan of the IP addresses associated with the domain name.
Ahn discloses a SYN-ACK message (Ahn: para.0024 “timestamp” para.0030 “Proxy device 112 may utilize the parameters to generate packets comprising data configured to establish a connection between proxy device 112 and host 106 (e.g., a TCP: SYN-ACK handshake message) and, at step #12, may communicate the packets to host 106. Rules 212 may be configured to cause rule gate 120 to one or more of identify the packets, determine (e.g., based on one or more network addresses included in their network-layer headers) that the packets comprise data corresponding to the network-threat indicators, for example, by correlating the packets with one or more of the packets comprising the DNS query or the reply to the DNS query based on data stored in logs 214 (e.g., the log data generated by rule gate 126 in one or more of steps # 6 or #7), and one or more of log or drop the packets.” Para.0020 “The threat-intelligence reports may include one or more network-threat indicators, for example, domain names (e.g., fully qualified domain names (FQDNs)), URIs, network addresses, or the like.” SYN-ACK packets are intercepted and checked for network threat indicators such as network address matches.)
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Huang with Ahn in order to incorporate a SYN-ACK message, and apply this concept to Huang such that SYN-ACK messages are considered in the network logs for identifying exposed assets.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved security (Ahn: para.0002).
However while Huang discloses matching addresses in general, Huang-Ahn does not explicitly disclose wherein the operations further comprise determining the source network address is matched to both the timestamped SYN-ACK message and the timestamped domain scan of the IP addresses associated with the domain name.
Cross discloses wherein the operations further comprise determining the source network address is matched to both the message and the domain scan of the IP addresses associated with the domain name (Cross: col. 61 line 60-col. 62 line 24 “The method 1800 begins at process 1802 with the remediation manager 1714 of the remediation system 114 receiving device connectivity data (e.g., as discussed above, with reference to FIGS. 1-11) for an entity (e.g., vendor). The device connectivity data can be received from a search and discovery engine for internet-connected devices, such as Shodan. … The properties can include device-related data and/or IP traffic data. … Device-related data can include IP address(es),… port number(s), timestamp data, host name, etc. IP traffic data can include items included in packets, as described elsewhere herein..” col. 11 line 20-39 “ For example, in addition to a payload, application-layer and/or link-layer in an example packet, may contain a header and/or footer that may include a source address of the sending host (e.g., a user device)” col. 62 lines 25-52 “At process 1806, the remediation manager 1714 identifies a vulnerability associated with a particular property. …For example, for each property in the collection of properties parsed from the device connectivity data, the remediation system 114 may reference the remediation executable vault 1704. If the property is found in the remediation executable vault 1704 previously populated with external data from NVD or a similar entity, the remediation manager determines 1714 determines that the property is associated with a vulnerability.” the remediation system of Fig. 1 in the cyber security assurance system, the external attack surface management system, receives connectivity data including packets comprising headers and source addresses, and compared them in steps 1804-1806 to identify vulnerabilities in the network).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date to combine Huang with Cross in order to incorporate wherein the operations further comprise determining the source network address is matched to both the message and the domain scan of the IP addresses associated with the domain name, and apply this concept to the timestamped SYN-ACK message and the timestamped domain scan of Huang-Ahn.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved cybersecurity by detecting and addressing cyber security vulnerabilities (Cross: col. 4 lines 4-47).
Regarding Claim 20, Huang-Ahn-Cross discloses claim 15 as set forth above.
Huang further discloses wherein the operations further comprise determining a public network address and a port associated with the device identified as the exposed to the public Internet (Huang: para.0019 “As such, the attack surface may comprise identifiers for each entry point, such as host identifiers (hosts IDs), port identifiers, device identifiers, combinations thereof, and the like.” para.0074 “ The dashboard may provide contents generated from prioritized attack surface data structure 221A. Entries of a report (e.g., report 401 or report 402), such as entries with private IP addresses, may be investigated using dashboard 403. Inbound traffic may not be expected to private IP addresses, which if detected, may indicate that a firewall is misconfigured and allowing traffic from a known indicator of compromise. A user of user device 240 (e.g., an analyst) can gain further insight into this host using dashboard 403, as shown in the following example. The event data about hosts 10.244.74.35 and 10.256.255.12 is automatically correlated with threat intelligence and asset enrichment.” Para.0028 “Furthermore, the system determines which ports of the hosts may be exposed (e.g., to the internet) on these assets.” The address and ports of the exposed hosts are identified.).
Claim(s) 6, 13, is/are rejected under 35 U.S.C. 103 as being unpatentable over Huang et al. (hereinafter Huang US 2023/0344848 A1) in view of Ahn et al. (hereinafter Ahn, US 2022/0014538 A1) in view of Lyukshin et al. (hereinafter Lyukshin, US 2021/0021613 A1).
Regarding Claim 6, Huang-Ahn discloses claim 1 as set forth above.
Huang further discloses timestamps associated with the timestamped message (Huang: para.0047 “Network traffic log store 210 stores network traffic logs for a client domain 110. The network traffic logs may comprise timestamps indicating times when each message in a network traffic log was transmitted and received, as well as timestamps for when each network traffic log was obtained by the computing system 220.” Timestamps for the connection notification, i.e. the network traffic logs, are obtained.) and
timestamped scan of the IP addresses associated with the public Internet (Huang: para.0048 “For example, the threat data feeds may include markers of suspicious activity, such as anomalous communication behavior (e.g., sending and receiving messages at abnormal times, at abnormal time intervals or frequencies, or according to an irregular schedule) or other anomalous network events.” Para.0051 “For example, log-threat correlation module 202 scans a list of malicious indicators in threat data store 212 and compares each entry to each network log in the network traffic log store 210 that is associated with the client domain 110. If there is a match between a malicious indicator from threat data store 212 and an identifier found in a network traffic log for client domain 110 (e.g., matching IP address, domain name, or other unique identifier or network address)” para.0028 “ To discover the internet facing assets, the network logs are correlated to threat intelligence (e.g., threat data feeds).” para.0047 “ The network traffic logs may comprise timestamps indicating times when each message in a network traffic log was transmitted and received” Para.0048 “Threat data store 212 stores …, including time of threats” Timestamps associated with threats for internet facing assets, i.e. from a scan, are obtained.).
However Huang does not explicitly disclose comparing timestamps associated with the timestamped SYN-ACK message to the timestamped scan of the IP addresses associated with the public Internet.
Ahn discloses a SYN-ACK message (Ahn: para.0024 “timestamp” para.0030 “Proxy device 112 may utilize the parameters to generate packets comprising data configured to establish a connection between proxy device 112 and host 106 (e.g., a TCP: SYN-ACK handshake message) and, at step #12, may communicate the packets to host 106. Rules 212 may be configured to cause rule gate 120 to one or more of identify the packets, determine (e.g., based on one or more network addresses included in their network-layer headers) that the packets comprise data corresponding to the network-threat indicators, for example, by correlating the packets with one or more of the packets comprising the DNS query or the reply to the DNS query based on data stored in logs 214 (e.g., the log data generated by rule gate 126 in one or more of steps # 6 or #7), and one or more of log or drop the packets.” Para.0020 “The threat-intelligence reports may include one or more network-threat indicators, for example, domain names (e.g., fully qualified domain names (FQDNs)), URIs, network addresses, or the like.” SYN-ACK packets are intercepted and checked for network threat indicators such as network address matches.)
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Huang with Ahn in order to incorporate a SYN-ACK message, and apply this concept to Huang such that SYN-ACK messages are considered in the network logs for identifying exposed assets.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved security (Ahn: para.0002).
However Huang-Anh does not explicitly disclose comparing timestamps associated with the timestamped SYN-ACK message to the timestamped scan of the IP addresses associated with the public Internet.
Lyukshin discloses comparing an event timestamp to another event timestamp (Lyukshin: para.0011 “In an exemplary aspect for correlating events to detect an information security incident, a correlation module may receive (e.g., from an event-generating module) a plurality of network events indicating potential security violations, wherein each network event of the plurality of network events has a respective timestamp. The correlation module may identify, from the plurality of network events, a subset of network events that have occurred within a period of time, based on each respective timestamp.” The timestamps of network events may be correlated together based on the events occurring within a period of time. Examiner notes that in view of para.0003 of applications specification, “When the connection notification and the scan have matching IP addresses and ports within a timeframe (such as 30 minutes), then the EASM service identifies the corresponding client device as being exposed to the public Internet.” This comparison checks to see if the matching events having matching attributes are within the same timeframe.).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Huang with Lyukshin in order to incorporate comparing an event timestamp to another event timestamp, such that the comparison step in Huang-Ahn that compares the timestamped SYN-ACK message to that of the threat data store information also considers their recorded timestamps to determine a correlation, in addition to the address and port similarities.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of identification of similar events to improve accuracy in identification of security risks (Lyukshin: para.0012 para.0116).
Regarding Claim 13, Huang discloses claim 8 as set forth above.
Huang further discloses wherein the operations further comprise timestamps between the timestamped message (Huang: para.0047 “Network traffic log store 210 stores network traffic logs for a client domain 110. The network traffic logs may comprise timestamps indicating times when each message in a network traffic log was transmitted and received, as well as timestamps for when each network traffic log was obtained by the computing system 220.” Timestamps for the connection notification, i.e. the network traffic logs, are obtained.)
the timestamped domain scan of the IP network addresses associated with the domain name (Huang: para.0048 “For example, the threat data feeds may include markers of suspicious activity, such as anomalous communication behavior (e.g., sending and receiving messages at abnormal times, at abnormal time intervals or frequencies, or according to an irregular schedule) or other anomalous network events.” Para.0051 “For example, log-threat correlation module 202 scans a list of malicious indicators in threat data store 212 and compares each entry to each network log in the network traffic log store 210 that is associated with the client domain 110. If there is a match between a malicious indicator from threat data store 212 and an identifier found in a network traffic log for client domain 110 (e.g., matching IP address, domain name, or other unique identifier or network address)” para.0028 “ To discover the internet facing assets, the network logs are correlated to threat intelligence (e.g., threat data feeds).” para.0047 “ The network traffic logs may comprise timestamps indicating times when each message in a network traffic log was transmitted and received” Para.0048 “Threat data store 212 stores …, including time of threats” Timestamps associated with threats for internet facing assets, i.e. from a domain scan, are obtained.).
However Huang does not explicitly disclose wherein the operations further comprise comparing timestamps between the timestamped SYN-ACK message and the timestamped domain scan of the IP addresses associated with the domain name.
Ahn discloses a SYN-ACK message (Ahn: para.0024 “timestamp” para.0030 “Proxy device 112 may utilize the parameters to generate packets comprising data configured to establish a connection between proxy device 112 and host 106 (e.g., a TCP: SYN-ACK handshake message) and, at step #12, may communicate the packets to host 106. Rules 212 may be configured to cause rule gate 120 to one or more of identify the packets, determine (e.g., based on one or more network addresses included in their network-layer headers) that the packets comprise data corresponding to the network-threat indicators, for example, by correlating the packets with one or more of the packets comprising the DNS query or the reply to the DNS query based on data stored in logs 214 (e.g., the log data generated by rule gate 126 in one or more of steps # 6 or #7), and one or more of log or drop the packets.” Para.0020 “The threat-intelligence reports may include one or more network-threat indicators, for example, domain names (e.g., fully qualified domain names (FQDNs)), URIs, network addresses, or the like.” SYN-ACK packets are intercepted and checked for network threat indicators such as network address matches.)
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Huang with Ahn in order to incorporate a SYN-ACK message, and apply this concept to Huang such that SYN-ACK messages are considered in the network logs for identifying exposed assets.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved security (Ahn: para.0002).
However Huang-Anh does not explicitly disclose wherein the operations further comprise comparing timestamps between the timestamped SYN-ACK message and the timestamped domain scan of the IP addresses associated with the domain name.
Lyukshin discloses comparing an event timestamp to another event timestamp (Lyukshin: para.0011 “In an exemplary aspect for correlating events to detect an information security incident, a correlation module may receive (e.g., from an event-generating module) a plurality of network events indicating potential security violations, wherein each network event of the plurality of network events has a respective timestamp. The correlation module may identify, from the plurality of network events, a subset of network events that have occurred within a period of time, based on each respective timestamp.” The timestamps of network events may be correlated together based on the events occurring within a period of time. Examiner notes that in view of para.0003 of applications specification, “When the connection notification and the scan have matching IP addresses and ports within a timeframe (such as 30 minutes), then the EASM service identifies the corresponding client device as being exposed to the public Internet.” This comparison checks to see if the matching events having matching attributes are within the same timeframe.).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Huang with Lyukshin in order to incorporate comparing an event timestamp to another event timestamp, such that the comparison step in Huang-Ahn that compares the timestamped SYN-ACK message to that of the threat data store information also considers their recorded timestamps to determine a correlation, in addition to the address and port similarities.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of identification of similar events to improve accuracy in identification of security risks (Lyukshin: para.0012 para.0116).
Claim(s) 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Huang et al. (hereinafter Huang US 2023/0344848 A1) in view of Ahn et al. (hereinafter Ahn, US 2022/0014538 A1) in view of Cross et al. (hereinafter Cross, US 11,720,686 B1) in view of Lyukshin et al. (hereinafter Lyukshin, US 2021/0021613 A1).
Regarding Claim 19, Huang-Ahn-Cross discloses claim 15 as set forth above.
Huang further discloses wherein the operations further comprise timestamps between the timestamped message (Huang: para.0047 “Network traffic log store 210 stores network traffic logs for a client domain 110. The network traffic logs may comprise timestamps indicating times when each message in a network traffic log was transmitted and received, as well as timestamps for when each network traffic log was obtained by the computing system 220.” Timestamps for the connection notification, i.e. the network traffic logs, are obtained.)
the timestamped domain scan of the IP addresses associated with the domain name (Huang: para.0048 “For example, the threat data feeds may include markers of suspicious activity, such as anomalous communication behavior (e.g., sending and receiving messages at abnormal times, at abnormal time intervals or frequencies, or according to an irregular schedule) or other anomalous network events.” Para.0051 “For example, log-threat correlation module 202 scans a list of malicious indicators in threat data store 212 and compares each entry to each network log in the network traffic log store 210 that is associated with the client domain 110. If there is a match between a malicious indicator from threat data store 212 and an identifier found in a network traffic log for client domain 110 (e.g., matching IP address, domain name, or other unique identifier or network address)” para.0028 “ To discover the internet facing assets, the network logs are correlated to threat intelligence (e.g., threat data feeds).” para.0047 “ The network traffic logs may comprise timestamps indicating times when each message in a network traffic log was transmitted and received” Para.0048 “Threat data store 212 stores …, including time of threats” Timestamps associated with threats for internet facing assets, i.e. from a domain scan, are obtained.).
However Huang does not explicitly disclose wherein the operations further comprise comparing timestamps between the timestamped SYN-ACK message and the timestamped domain scan of the IP addresses associated with the domain name.
Ahn discloses a SYN-ACK message (Ahn: para.0024 “timestamp” para.0030 “Proxy device 112 may utilize the parameters to generate packets comprising data configured to establish a connection between proxy device 112 and host 106 (e.g., a TCP: SYN-ACK handshake message) and, at step #12, may communicate the packets to host 106. Rules 212 may be configured to cause rule gate 120 to one or more of identify the packets, determine (e.g., based on one or more network addresses included in their network-layer headers) that the packets comprise data corresponding to the network-threat indicators, for example, by correlating the packets with one or more of the packets comprising the DNS query or the reply to the DNS query based on data stored in logs 214 (e.g., the log data generated by rule gate 126 in one or more of steps # 6 or #7), and one or more of log or drop the packets.” Para.0020 “The threat-intelligence reports may include one or more network-threat indicators, for example, domain names (e.g., fully qualified domain names (FQDNs)), URIs, network addresses, or the like.” SYN-ACK packets are intercepted and checked for network threat indicators such as network address matches.)
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Huang with Ahn in order to incorporate a SYN-ACK message, and apply this concept to Huang such that SYN-ACK messages are considered in the network logs for identifying exposed assets.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of improved security (Ahn: para.0002).
However Huang-Anh does not explicitly disclose wherein the operations further comprise comparing timestamps between the timestamped SYN-ACK message and the timestamped domain scan of the IP addresses associated with the domain name.
Lyukshin discloses comparing an event timestamp to another event timestamp (Lyukshin: para.0011 “In an exemplary aspect for correlating events to detect an information security incident, a correlation module may receive (e.g., from an event-generating module) a plurality of network events indicating potential security violations, wherein each network event of the plurality of network events has a respective timestamp. The correlation module may identify, from the plurality of network events, a subset of network events that have occurred within a period of time, based on each respective timestamp.” The timestamps of network events may be correlated together based on the events occurring within a period of time. Examiner notes that in view of para.0003 of applications specification, “When the connection notification and the scan have matching IP addresses and ports within a timeframe (such as 30 minutes), then the EASM service identifies the corresponding client device as being exposed to the public Internet.” This comparison checks to see if the matching events having matching attributes are within the same timeframe.).
Therefore it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine Huang with Lyukshin in order to incorporate comparing an event timestamp to another event timestamp, such that the comparison step in Huang-Ahn that compares the timestamped SYN-ACK message to that of the threat data store information also considers their recorded timestamps to determine a correlation, in addition to the address and port similarities.
One of ordinary skill in the art would have been motivated to combine because of the expected benefit of identification of similar events to improve accuracy in identification of security risks (Lyukshin: para.0012 para.0116).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Du Preez et al. US 2025/0310367 A1, see para.0157-0159 showing port scans and address scans for hosts to determine internet facing assets, the process in more detail in Fig. 8.
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to EUI H KIM whose telephone number is (571)272-8133. The examiner can normally be reached 7:30-5 M-R, M-F alternating.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kamal B Divecha can be reached at 5712725863. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/EUI H KIM/ Examiner, Art Unit 2453
/KAMAL B DIVECHA/ Supervisory Patent Examiner, Art Unit 2453