DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claims 1-3 and 6-14 are pending with independent claim 1.
Priority
Receipt is acknowledged of certified copies of papers required by 37 CFR 1.55.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 11/12/2024 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 5/15/2026 has been entered.
Response to Arguments
Applicant’s arguments, see page(s) 6, filed 5/15/2026, with respect to the objection(s) to claim(s) 1-3 and 6-14 have been fully considered and are persuasive. The associated objection(s) to the listed claim(s) has/have been withdrawn.
Applicant's arguments, see page 6, filed 5/15/2026, with respect to the objection to the abstract have been fully considered but they are not persuasive. This objection is maintained.
In response to requests:
“(1) identify support for the objection in the M.P.E.P.”
Support may be found in MPEP 608.01(b) Abstract of the Disclosure, section 1C, “The language should be clear and concise and should not repeat information given in the title.”
“(2) provide a suggestion for amending the abstract to introduce the invention without referring to the invention (i.e., the title of the invention).”
Examiner notes that such a suggestion was provided in the previous office action; however, it will be repeated here for convenience. The objection may be overcome by simply removing the first sentence of the abstract, as it provides no information not already provided in the title.
Applicant's arguments, see pages 7-10, filed 5/15/2026, with respect to the rejection of claims 1-3 and 6-14 under 103 have been fully considered and are persuasive. Therefore, the rejection has been withdrawn. However, upon further consideration, a new ground(s) of rejection is made in view of SIMS et al (Doc ID US 20230137747 A1).
Specification
The abstract of the disclosure is objected to because:
It repeats information given in the title. Specifically, the first sentence of the abstract, “A method for controlling the access of a user to a network includes …” repeats the title nearly verbatim.
A corrected abstract of the disclosure is required and must be presented on a separate sheet, apart from any other text. See MPEP § 608.01(b).
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION. — The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
Claim(s) 1-3 and 6-14 is/are rejected under 35 U.S.C. 112(b) as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor regards as the invention.
Regarding claim 1:
A broad range or limitation together with a narrow range or limitation that falls within the broad range or limitation (in the same claim) may be considered indefinite if the resulting claim does not clearly set forth the metes and bounds of the patent protection desired. See MPEP § 2173.05(c). In the present instance, claim 1 recites the broad recitation, “… determining a monitoring parameter corresponding to the access of the user to: at least one program; or at least one service; or at least one file of the network …”, and the claim also recites, “… said determining the monitoring parameter is dependent on a number of files of the network or of the data processing device opened by the user …”, which is the narrower statement of the range/limitation. The claim(s) are considered indefinite because there is a question or doubt as to whether the feature introduced by such narrower language is (a) merely exemplary of the remainder of the claim, and therefore not required, or (b) a required feature of the claims.
Regarding claim(s) 2, 3, and 6-14:
They are dependent on one or more rejected claims, and thus inherit those rejections. This rejection(s) could be overcome by overcoming the rejection(s) to any claims upon which these claims depend, or by amending the claim(s) such that they are no longer dependent on any rejected claim.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claims 1, 2, 6, and 8-14 are rejected under 35 U.S.C. 102(a)(2) as being anticipated by SIMS et al (Doc ID US 20230137747 A1).
Examiner notes that the prior art of SIMS claims benefit to the earlier filing date of provisional patent application US 63273024, which supports the relevant subject matter and has been included in the file wrapper for Applicant’s convenience.
Regarding claim 1:
SIMS teaches:
A method for controlling an access of a user to a network, the method comprising: after the user has been granted access to the network, determining a monitoring parameter corresponding to the access of the user to: at least one program; or at least one service; or at least one file of the network ([0031] "Indexing service 132 may establish the file access limits 138 based on the mean number of accesses for each user ID, user group, or all user IDs in the enterprise over one or more observation periods");
comparing the monitoring parameter with a first limit value ([0024] "… filewall service 124 can compare the file access metrics 142 provided by file access index 136 to file access limits 138 in order to detect and address abnormal file system access patterns."); and
disconnecting the access of the user to the network depending on the result of the comparison when the monitoring parameter is greater than the first limit value ([0024] "… Filewall service 124 can add user IDs contributing to an abnormal file system access pattern to a block list 140. ... to cause hardware platform(s) 112 to temporarily or permanently block network traffic of user IDs contributing to the abnormal file system access pattern ..."),
wherein said determining the monitoring parameter is dependent on a number of files of the network or of the data processing device opened by the user, ([0035] "... indexing service 132 detects each file system access request made by computing nodes 102 to file system 130 .... Based on these event messages, indexing service 132 populates file access index 136 with access metrics 142 for each user ID ...") and
wherein the number of files opened by the user comprises at least one action including opening, reading, writing, renaming, copying or deleting a file of the network or of the data processing device ([0023] "... Each event message can include, for example, an identifier of a file system object 108 to which access is requested ..., the access type (e.g., open, save, delete, etc.), the user identifier (ID) to which the access request is attributed …").
Regarding claim 2:
SIMS teaches:
The method according to claim 1, wherein the method controls the access of a user to a data processing device of the network, wherein the monitoring parameter corresponds to the access of the user to: at least one program or at least one service or at least one file of the data processing device, (SIMS [0018] "… the file system objects 108 of file system 130 can be physically stored locally on file server 110 …" and [0035] "... indexing service 132 detects each file system access request made by computing nodes 102 to file system 130 …") or
wherein the access of the user to the data processing device is disconnected depending on the result of the comparison (SIMS [0024] "… Filewall service 124 can add user IDs contributing to an abnormal file system access pattern to a block list 140. ... to cause hardware platform(s) 112 to temporarily or permanently block network traffic of user IDs contributing to the abnormal file system access pattern ...").
Regarding claim 6:
SIMS teaches:
The method according to claim 1, wherein the monitoring parameter is determined over a predefined period of time, which is defined by an administrator of the network or of the data processing device (SIMS [0031] "Indexing service 132 may establish the file access limits 138 based on the mean number of accesses for each user ID, user group, or all user IDs in the enterprise over one or more observation periods").
Regarding claim 8:
SIMS teaches:
The method according to claim 1, wherein the disconnection of the access of the user to the network is carried out by at least one step: terminating the current network session of the user; denying the user further access to at least one or all files of the network; (SIMS [0024] "… Filewall service 124 can add user IDs contributing to an abnormal file system access pattern to a block list 140. ... to cause hardware platform(s) 112 to temporarily or permanently block network traffic of user IDs contributing to the abnormal file system access pattern ..."); or blocking at least one user-defined port of the user for access to the network.
Regarding claim 9:
SIMS teaches:
The method according to claim 1, wherein the disconnection of the access of the user to the network occurs by denying at least one access authorization of the user by denying all access authorizations of the user (SIMS [0024] "… Filewall service 124 can add user IDs contributing to an abnormal file system access pattern to a block list 140. ... to cause hardware platform(s) 112 to temporarily or permanently block network traffic of user IDs contributing to the abnormal file system access pattern ...").
Regarding claim 10:
SIMS teaches:
The method according to claim 1, wherein, before the determination of the monitoring parameter, a user group is created, and wherein each member of the user group is denied write or read authorization or any access authorization, ([0024] "… Filewall service 124 can add user IDs contributing to an abnormal file system access pattern to a block list 140.") and
upon disconnection of the access of the user to the network or to the data processing device, the user is assigned to the user group ([0027] "… If packet controller 204 determines via block list cache 120 that a match exists in block list 140 for a user ID ... packet controller 204 blocks access by the user ID to the filepath of the requested file system operation …").
Regarding claim 11:
SIMS teaches:
The method according to claim 1, wherein a warning signal is outputted to the user or to an administrator of the network or of the data processing device, depending on a comparison of the monitoring parameter with a second limit value which is different from the first limit value or which is smaller than the first limit value (SIMS [0031] "… In some embodiments, the file access limits 138 can include an alert limit specifying a number of file accesses within one or more observation intervals ... that will cause an alert (e.g., to one or more users, a file system administrator, an enterprise administrator, etc.) to be generated.").
Regarding claim 12:
SIMS teaches:
The method according to claim 1, further comprising: performing a query as to whether the user is present in an existing user database of the network or of the data processing device ([0027] "... Packet controller 204 inspects incoming ... traffic received by network adapter 122 from computing devices 102 and compares the requesting user ID and/or file path of a requested file system operation."); and
disconnecting the access of the user to the network or to the data processing device if the user is not present in the user database ([0027] "… If packet controller 204 determines via block list cache 120 that a match exists in block list 140 for a user ID ... packet controller 204 blocks access by the user ID to the filepath of the requested file system operation …").
Regarding claim 13:
SIMS teaches:
A network comprising: at least one data processing device designed to carry out the method according to claim 1 (SIMS [0022] "... computing environment 100 additionally includes a filewall service 124, which can be implemented ... on one or more hardware platforms 126. Hardware platforms 126 can be implemented with components (e.g., processor core(s) 114, local storage 116, and network adapter 112) ...").
Regarding claim 14:
SIMS teaches:
A non-transitory computer readable medium comprising program code to carry out the steps of the method according to claim 1 if the computer program code is run on a data processing device of the network (SIMS [0022] "... computing environment 100 additionally includes a filewall service 124, which can be implemented ... on one or more hardware platforms 126. Hardware platforms 126 can be implemented with components (e.g., processor core(s) 114, local storage 116, and network adapter 112) ...").
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim 3 is rejected under 35 U.S.C. 103 as being unpatentable over SIMS et al (Doc ID US 20230137747 A1) as applied to claim 1 above, and further in view of CHAVEZ et al (Doc ID US 20220321842 A1).
Regarding claim 3:
SIMS teaches:
The method according to claim 1,
CHAVEZ teaches the following limitations not taught by SIMS:
wherein, in the case in which the user deactivates at least one predefined program or a service of the network ([0124] "… For example, if a user deactivated an antivirus program, a workflow may comprise …"), in particular of the data processing device, the monitoring parameter is set to a predefined value such that the disconnection of the access of the user to the network or to the data processing device occurs ([0124] "… a new workflow may comprise instructions as to what actions should be performed. Actions may be, for example, ... block a port or user ...").
Blocking a user’s access in response to the user shutting off a service is a known technique in the art, as demonstrated by CHAVEZ. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the network access security method of SIMS with the user disconnect based on user actions of CHAVEZ with the motivation to prevent users from disabling network services which may hinder malicious actions. It is obvious to disconnect a user for unauthorized closing of network services.
Claim 7 is rejected under 35 U.S.C. 103 as being unpatentable over SIMS et al (Doc ID US 20230137747 A1) as applied to claim 1 above, and further in view of COVELL et al (Doc ID US 20230058138 A1).
Regarding claim 7:
SIMS teaches:
The method according to claim 1,
COVELL teaches the following limitations not taught by SIMS:
wherein the first limit value is predefined by an administrator of the network or of the data processing device, or is determined by a learning phase over a user-defined period of time ([0026] "... authentication manager 110 can ... set risk threshold for each topic. For example, authentication manager 110 can ... classify interactions ... by respective topics that each have corresponding levels of risk. For example, topics can include “system access” and requests thereof, “sensitive data” and requests thereof ...").
Using administrator input as a monitoring parameter is a known technique in the art, as demonstrated by COVELL. It would have been obvious to a PHOSITA before the effective filing date of the claimed invention to modify the network access security method of SIMS with the administrator input of COVELL with the motivation to make the system flexible so that administrators can choose the most appropriate elements of their network to monitor.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
LITTLE et al (Doc ID US 20200302074 A1) teaches a similar method of monitoring user behavior based on file access, but does not disconnect the user after a finding.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to BRANDON BINCZAK whose telephone number is (703)756-4528. The examiner can normally be reached M-F 0800-1700.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Alexander Lagor can be reached on (571) 270-5143. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/BB/Examiner, Art Unit 2437
/ALEXANDER LAGOR/Supervisory Patent Examiner, Art Unit 2437