DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendment
This is a reply to the amendment filed on 05/04/2026, in which, claim(s) 1-2, 4-10, 14-15, 17, 19-23 and 27 are pending. Claim(s) 1-2, 7, 10, 14-15, 20, 23 and 27 are amended. Claim(s) 3, 11-13, 16, 18, and 24-26 are cancelled. No claim(s) are newly added.
Response to Arguments
Specification Objection:
Applicant’s arguments with respect to specification objection have been considered. The specification objection has been withdrawn in view of the amendment to the specification (the abstract).
Claim Objection:
Applicant’s arguments with respect to objection of claim(s) 1-2, 7, 10, 14-15, 20, 23 and 27 have been considered. The objection of claim(s) 1-2, 7, 10, 14-15, 20, 23 and 27 have been withdrawn in view of the amendment to claim.
Double Patenting (DP):
Applicant submitted an eTD on 05/04/2026 to overcome DP rejection issued in the previous office action. The eTD has been approved. The DP rejection issued in the previous action has been withdrawn.
Claim Rejections - 35 U.S.C. § 102 and 35 U.S.C. § 103:
Applicant’s arguments with respect to the rejection of claim(s) 1-2, 4-10, 14-15, 17, 19-23 and 27 have been considered but are moot in view of the new ground(s) of rejection.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claims 1-2, 4-10, 14-15, 17, 19-23 and 27 are rejected under 35 U.S.C. 103 as being unpatentable over Ben Ezra et al. (US 2018/0069876 A1) in view of Sebastien Meriot (US 2020/0007575 A1) further in view of Sonnenberg (US 2016/0261615 A1).
Regarding Claims 1, 14, and 27, Ben Ezra discloses
obtain: (a) an attack-vector scenario, the attack-vector scenario comprising a sequence of cyber tactics, each of the cyber tactics being associated with one or more respective cyber techniques which are possible manifestations of the corresponding cyber tactic in the context of the attack-vector scenario ([0009], “a DDoS burst attack is a sequence of high traffic volumes communicated in bursts. A sequence of actions would include intermittent bursts of attack traffic and then pauses. As another example, a sequence of actions can begin with information gathering, continue with lateral movement, and end in data exfiltration”) , at least one cyber technique is associated with at least one sequence of events that can execute on one or more processors of at least one entity of a plurality of entities of an organizational network, wherein execution of the at least one sequence of events indicates implementation of the respective cyber technique, and (b) information about actual sequences of events that executed on the one or more processors ([0053], “at S320, every pair of event sequences in the list of sequences are compared to each other to identify patterns having similar behavior. In an embodiment, S320 includes listing, for each sequence, its fixed and step features (Ffixed and Fstep); comparing each fixed feature (Ffixed) of one sequence to Fstep of another sequence; identifying patterns of similar steps (based on the Ffixed and Fstep)”);
identify, based on the information, the cyber techniques that occurred on the organizational network by matching the actual sequences of events with the at least one sequence of events associated with the cyber techniques, giving rise to implemented cyber techniques ([0059-0061], “At S520, the new event is matched to any event sequence created during the learning process in order to update any such sequence. In an embodiment, S520 can be performed using the sequencing process described in FIG. 4”, “At S530, any updated sequences of events, new sequences of events, or a combination thereof, created in response to the matching performed at S520 is compared to the identified attack patterns”); and
alert a user of the cyber security system of a potential cyber-attack upon determining that each of the cyber tactics forming the attack vector scenario, is associated with at least one of the implemented cyber techniques ([0062], “At S550, it is checked if the risk score is above a predefined threshold. If so, execution continues with S560, at which an alert is generated”),
Ben Ezra does not explicitly teach but Meriot teaches
sequences of events are sequences of machine language instructions ([0028], “locating a predetermined machine language instruction sequence in the malware”);
Ben Ezra and Meriot are analogous art as they are in the same field of endeavor of information security. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Meriot with the disclosure of Ben Ezra. The motivation/suggestion would have been for defending an infrastructure against a distributed denial of service (DDoS) attack (Meriot, [0030]).
The combined teaching of Ben Ezra and Meriot does not explicitly teach but Sonnenberg teaches
wherein the information about the actual sequences of machine language instructions is obtained by a trapping mechanism, capable of retrieving machine language instructions from an instruction unit, storing fetched machine learning instruction for at least one processor of the processors (Sonnenberg, [0050], “The NLEDM 512 is comprised of machine or instruction level event trapping algorithms that detect low-level attacks intended to directly disrupt the operations of the network node 102. As such, the event trapping algorithms described herein will advantageously be designed to detect low-level attacks (including code injection attacks) which interrupt or interfere with the machine code or machine language instructions which execute on processor 306”),
Ben Ezra, Meriot and Sonnenberg are analogous art as they are in the same field of endeavor of information security. It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to combine the teachings of Sonnenberg with the combined teaching of Ben Ezra and Meriot. The motivation/suggestion would have been for defending a communication network by using a distributed infrastructure that leverages coordination across disparate abstraction levels (Sonnenberg, Abstract).
Regarding Claims 2, and 15, the combined teaching of Ben Ezra, Meriot and Sonnenberg teaches
wherein alerting the user of the potential cyber-attack is upon further determining that a causality connection exists between one or more of the implemented cyber techniques associated with each given cyber tactic of the cyber tactics and one or more of the implemented cyber techniques associated with a subsequent cyber tactic subsequent to the given cyber tactic (Ben Ezra, [0010], “analyze connections of events across different devices”, [0030], “an attack prediction system 150 is also communicatively connected to the network 120 and configured to perform the various disclosed embodiments for predictive cyber-attack detection”).
Regarding Claims 4, and 17, the combined teaching of Ben Ezra, Meriot and Sonnenberg teaches
wherein: (a) at least one machine language instruction of the sequence of machine language instructions comprises one or more first opcodes, and (b) the identification of the implemented cyber techniques is based on matching the opcodes comprised in the actual sequences of machine language instructions with second opcodes comprised in the at least one sequence of machine language instructions (Meriot, [0092], “the ciphering key is automatically recuperated by searching for a predetermined operation code sequence that is indicative of a ciphering routine used in the malware. This opcode sequence may contain other operation codes besides PUSH and MOV. As a non-limiting example, FIG. 7 is an illustration of a routine used by the malware MIRAI to encrypt character chains. A On FIG. 7, a routine 500 defines a value 510 labelled “table_key”. The table_key 510 is placed in variables k1, k2, k3 and k4 using SHIFT operation codes. A SHIFT 24 operation code 520 actually shifts the table_key 510 by 24 bits into variable k4. While SHIFT operations by 8 or 16 bits are not uncommon, the SHIFT 24 operation code 520 is an infrequently (or rarely) used operation code and provides a clue to the reverse engineering process of the location of the ciphering key. Otherwise stated, the SHIFT 24 operation code 520 is part of a signature of the malware MIRAI. Previous experience acquired from reverse engineering applied to other malwares may be put to use to identify specific operation codes as potential markers for corresponding malwares”).
Regarding Claim 5, the combined teaching of Ben Ezra, Meriot and Sonnenberg teaches
wherein the at least one sequence of machine language instructions is at least a partial translation of code realizing the corresponding cyber technique into machine langue instructions (Meriot, [0092], “This opcode sequence may contain other operation codes besides PUSH and MOV. As a non-limiting example, FIG. 7 is an illustration of a routine used by the malware MIRAI to encrypt character chains. A On FIG. 7, a routine 500 defines a value 510 labelled “table_key”. The table_key 510 is placed in variables k1, k2, k3 and k4 using SHIFT operation codes. A SHIFT 24 operation code 520 actually shifts the table_key 510 by 24 bits into variable k4. While SHIFT operations by 8 or 16 bits are not uncommon, the SHIFT 24 operation code 520 is an infrequently (or rarely) used operation code and provides a clue to the reverse engineering process of the location of the ciphering key. Otherwise stated, the SHIFT 24 operation code 520 is part of a signature of the malware MIRAI. Previous experience acquired from reverse engineering applied to other malwares may be put to use to identify specific operation codes as potential markers for corresponding malwares”).
Regarding Claims 6, and 19, the combined teaching of Ben Ezra, Meriot and Sonnenberg teaches
wherein the at least one sequence of machine language instructions includes one or more suspicious machine langue instructions, being machine learning instructions being a translation of suspicious code (Meriot, [0098], “the SHIFT 24 operation code 520 is part of a signature of the malware MIRAI. Previous experience acquired from reverse engineering applied to other malwares may be put to use to identify specific operation codes as potential markers for corresponding malwares”).
Regarding Claims 7, and 20, the combined teaching of Ben Ezra, Meriot and Sonnenberg teaches
wherein: (a) at least one cyber technique is associated with a corresponding event type of a plurality of event types that occur on the one or more entities of the organizational network, wherein occurrence of an actual event of the respective event type indicates implementation of the respective cyber technique, (b) the information further includes actual events that occurred on the one or more entities of the organizational network, wherein each of the actual events is associated with a respective actual event type, and (c) the identification of the implemented cyber techniques is further based on matching the actual event types with the event types associated with the cyber techniques, giving rise to implemented cyber techniques (Ben Ezra, [0009], “a DDoS burst attack is a sequence of high traffic volumes communicated in bursts. A sequence of actions would include intermittent bursts of attack traffic and then pauses. As another example, a sequence of actions can begin with information gathering, continue with lateral movement, and end in data exfiltration”, [0053], “at S320, every pair of event sequences in the list of sequences are compared to each other to identify patterns having similar behavior. In an embodiment, S320 includes listing, for each sequence, its fixed and step features (Ffixed and Fstep); comparing each fixed feature (Ffixed) of one sequence to Fstep of another sequence; identifying patterns of similar steps (based on the Ffixed and Fstep)”).
Regarding Claims 8, and 21, the combined teaching of Ben Ezra, Meriot and Sonnenberg teaches
wherein the information is obtained periodically or continuously and wherein the identify and the alert are performed periodically or continuously while maintaining previously identified implemented cyber techniques (Ben Ezra, [0015], “periodically receiving new security events”, [0062], “At S550, it is checked if the risk score is above a predefined threshold. If so, execution continues with S560, at which an alert is generated” periodically or continuously).
Regarding Claims 9, and 22, the combined teaching of Ben Ezra, Meriot and Sonnenberg teaches
predict, based on: (a) the attack-vector scenario, (b) the implemented cyber techniques, and (c) the previously identified implemented cyber techniques, a next step cyber tactic of the cyber tactics; and perform a prevention action to prevent the next step cyber tactic (Ben Ezra, [0030], “an attack prediction system 150 is also communicatively connected to the network 120 and configured to perform the various disclosed embodiments for predictive cyber-attack detection. Specifically, the attack prediction system 150 is configured to analyze events to generate sequences of events”, [0062]).
Regarding Claims 10, and 23, the combined teaching of Ben Ezra, Meriot and Sonnenberg teaches
wherein the prevention action is one or more of: (a) report the next step cyber tactic to the user of the cyber security system, (b) simulate the next step cyber tactic, or (c) implement one or more honeypots within one or more entities of the organizational network wherein events associated with the next step cyber tactic occurrence (Ben Ezra, [0062], “At S550, it is checked if the risk score is above a predefined threshold. If so, execution continues with S560, at which an alert is generated; otherwise, execution terminates. Alternatively, or collectively, S560 may include activating one more mitigation actions”).
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHENG-FENG HUANG whose telephone number is (571)272-6186. The examiner can normally be reached Monday-Friday: 9 am - 5 pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Eleni A Shiferaw can be reached at (571) 272-3867. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/CHENG-FENG HUANG/Primary Examiner, Art Unit 2497