CTNF 18/735,233 CTNF 90804 DETAILED ACTION 07-03-aia AIA 15-10-aia The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA. This Office action is responsive to the communication filed on 06/06/2024. The claims 1-20 are pending, of which the claim(s) 1, 8, & 14 is/are in independent form. 07-30-03-h AIA Claim Interpretation 07-30-03 AIA The following is a quotation of 35 U.S.C. 112(f): (f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. The following is a quotation of pre-AIA 35 U.S.C. 112, sixth paragraph: An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof. 07-30-06 This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitation(s) is/are: In claims 8- 13: “ an interaction 1 engine ”: see item 302, Fig. 3 & spec, para. 048, 042 “ an analysis engine ”: See, item 304 Fig. 3, Spec, para. 048, 043-045 “an investigation engine ”: See item 306 Fig.3, Spec para. 047-048 Because this/these claim limitation(s) is/are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, it/they is/are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof. If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. Claim Rejections - 35 USC § 103 07-20-aia AIA The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 07-23-aia AIA The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows: 1. Determining the scope and contents of the prior art. 2. Ascertaining the differences between the prior art and the claims at issue. 3. Resolving the level of ordinary skill in the pertinent art. 4. Considering objective evidence present in the application indicating obviousness or nonobviousness. 07-21-aia AIA Claim (s) 1-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Kaluza et al., (US 11290325 B1) in view of Pike et al., (US 20200404016 A1) . Regarding claim 1, Kaluza teaches a method [ actions performed at the “agent server 170 and stored in a database 160” ] comprising: (Figs. 1, 3); receiving [ the server 170 receiving information from stations 110, “the information (e.g. configuration parameters 150) collected by agent application 130 is provide to an agent server 170 ”] an asset modification indication [ fig. 4, item 415 and 420 ] representative of a first modification made to a first asset [“ stations 110 may be any type of general purpose computer” ] within a facility [ location where one or more stations 110 are installed ], wherein the asset modification indication comprises a first asset identifier [ any information that indicate station 110, e.g., “configuration parameters 150 may include hardware details of the station 110, for example the amount of RAM, processor model, disk size, and models of devices attached … virtual network device, virtual subnet, and similar item ”, “ ACISE) 320 that estimates authorization status…2. What changed and whether it corresponds to the approved change request scope and configuration item ”] associated with the first asset (Col 5 lines 1- 55, Col 9 lines 45-55); obtaining an operation shift report [ items 405 and 410, “change request record , deployment record or other type of record” provided in “text description in natural language , log output, etc.” and “include a change manifest .”] for the facility, wherein the operation shift report is indicative of modifications [e.g., start time, target environment, scope of change, “AI based changes 220 ”] made to assets within the facility (Col 6 lines 40-68, Col 7 lines 1- 35, Fig. 4); analyzing [“ a machine-learning process for natural language processing (NLP), for example analysing a change request description 1010 with natural language processing options 1020 to produce a semantically annotated change request description 1030 ”] the operation shift report using a natural language processing model [“ language processing options 1020” or machine learning for the natural language form of the change request records of fig. 4] to extract a first set of modification records associated with a first set of assets, wherein each of the first set of modification records comprises an asset identifier corresponding to an asset and modifications made to the asset, and the natural language processing model is trained [“ Optionally, each step of the process might need a machine-learning model trained and calibrated on change requests tickets 405 from a specific language domain, for example, a corpus of texts containing terminology, terms and expressions used in IT ”] using historical [“ by analysing historical change requests and implemented changes to identify what are the typical changes ”] operation shift reports including labeled modification records [e.g., “ containing terminology, terms”] associated with a plurality of assets (Fig. 10, Fig. 4, Col 12, lines 3- 15, Col 13 lines 10-55); identifying a first modification record [ change request record for a particular asset/station of “each change request” ] in the first set of modification records using at least one correlation parameter [ information included in the context identification like ‘scheduled maintenance window ’], wherein the first modification record corresponds to the first asset; correlating [“ the match between the change request and the actual change context with a context matching engine 430 ”] the first modification with the modifications included in the first modification record to generate a correlation score [“ For each change request record: Determine change request context Calculate authorization score with context matching engine (CME)”]; comparing [“authorization score exceeds the threshold” or not checking ] the correlation score with a confidence value [“ the threshold”] to verify the authenticity of the first modification; and (Fig. 4, Col 10 lines 1- 20, claim 1); initiating an action investigation with respect to the first modification upon determining the correlation score to be below [“ If there is not a change request record exceeding the authorization score, the change is sent to the next stage ” ] the confidence value and concluding the change request as unauthorized change(s) (Col 10 lines 15- 30, Fig. 3). Kaluza teaches its server 170’s comparing the correlation score with a confidence value to distinguish potentially-authorized or unauthorized changes (Fig. 3- 4). However, one still may challenge that mere sent to the next stage action(s) do/does not necessarily mean investigating the modification when the score is below the confidence value (is unauthorized change of S344) as claimed and shown above with the strikethrough emphasis. Hence, Kaluza may or may not necessarily anticipate the claim 1 although it may suggest the invention of this claim obvious to PHOSITA. Nevertheless, examiner further relies on disclosure of Pike to show explicit disclosure of the claimed limitation. Pike teaches a method and system including a management system 130 that detects an changes at the target/managed device 120 and determines whether the changes are authorized changes or unauthorized changes and reverting back the unauthorized changes after checking with multiple users (fig. 1, [013, 017, 082]). Specifically, Pike teaches A method comprising: receiving an asset modification indication representative of a first modification made to a first asset within a facility, wherein the asset modification indication comprises a first asset identifier associated with the first asset… initiating an investigation [ asking multiple users about the unauthorized change “No unauthorized changes will be granted without multiple users signing off on those changes ” or “and investigation is needed ”] with respect to the first modification upon determining the correlation score to be below the confidence value and unauthorized changes taking place ([017-018, 057-058, 0104]). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to (1) combine Pike and Kaluza because they both related to comparing information of the operation shift report with received asset modification requests to determine authorized and unauthorized changes and (2) modify the method/system of Kaluza to include step of initiating an investigation with respect to the first modification upon determining the correlation score to be below the confidence/threshold value. Doing so would allow to avoid unauthorized changes 344 taking effect in the monitored stations 110 and allow to recover from unauthorized changes that are already executed thereby bringing the changes into security compliance (Pike [017, 049]). Regarding claim 2, Kaluza in view of Pike teaches the method of claim 1, wherein the at least one correlation parameter comprises at least one of the first asset identifier [e.g., “ Location of the change in the IT environment ( e.g. host, node, environment)”] and a schedule [“ Identifying a time window when the change is allowed ”] of the first modification (Col 2 lines 20-30, Col 5 lines 10-25). Regarding claim 3, Kaluza in view of Pike teaches the method of claim 2, further comprising: obtaining at least one second asset identifier [ e.g., “Identifying a scope of the content that was changed”. Please note that claim covers every possible type of the asset identifiers] corresponding to the first asset identifier; and utilizing the at least one second asset identifier to identify the first modification record (Kaluza, Col 2 lines 20-30, Col 5 lines 10-25, claim 1). Regarding claim 4, Kaluza in view of Pike teaches the method of claim 1, wherein the asset modification indication is received during an operation shift [e.g., “ first Tuesday in a month .”] at the facility and the operation shift report corresponds to the operation shift (Kaluza claim 1, Fig. 4, Col 10 lines 30-40). Regarding claim 5, Kaluza in view of Pike teaches the method of claim 1, wherein the first modification comprises a modification in operational configuration [“the information (e.g. configuration parameters 150) collected by agent application 130 is provide to an agent server 170”] of the asset (Kaluza Col 5 lines 1-40). Regarding claim 6, Kaluza in view of Pike teaches the method of claim 5, further comprising initiating a configuration restoration operation [ “performs a rollback the moment the change that falls outside the exception list”] for the asset, wherein the configuration restoration operation comprises rolling back the first modification (Pike [058, 086]). Regarding claim 7, Kaluza in view of Pike teaches the method of claim 6, wherein initiating the configuration restoration operation comprises transmitting a notification indicating the first modification to be unauthorized to a Security Operations Center (SOC) [“ may be transmitted to the management system 130 ”, “ By providing alerts 174 to an administrator, e.g. to specific servers in the network or to mobile phones ;”] meant to monitor security related events for the facility (Pike [058-059], Col 6 lines 5-10). Regarding claim 8 , Kaluza teaches an unauthorized modification identification system (UMIS) [“ an information technology system 100 ” including an agent server 170 and stored in a database 160 .”] comprising: (Figs. 1, 3); an interaction engine [s erver 170’s CPU that receives data used for the stations 130s ] to: (Fig. 1); receive an asset modification indication [ item 150/155 of fig. 1 or items 415 and 420 of fig. 4 about one of the 3 types of the changes shown in fig. 3] representative of a first modification made to a first asset [e.g., “ each station 110 ”] within a facility, wherein the asset modification indication comprises a first asset identifier associated with the asset; and obtain an operation shift report [“ change request records” e.g., items 405 and item 410 of fig. 4] for the facility, wherein the operation shift report is indicative of modifications made to assets within the facility (Fig. 1); an analysis engine [ server 170’s CPU’s data analyzing portion ] coupled to the interaction engine to: (Fig. 1); analyze [t he NLP learning model reading the ‘change request records’ to compare to the change request ] the operation shift report using a natural language processing model [“ language processing options 1020” or machine learning for the natural language form of the change request records of fig. 4, “the change request record (or deployment record) may be provided in the form of semi-structured or unstructured data, that is, data that is not in a pre-defined data model or is not organized in a pre-defined manner, for example, text description in natural language ,”] to extract a first set of modification records, wherein each of the first set of modification records comprises an asset identifier corresponding to an asset and modifications made to the asset, and the natural language processing model [“ Optionally, each step of the process might need a machine-learning model trained and calibrated on change requests tickets 405 from a specific language domain, for example, a corpus of texts containing terminology, terms and expressions used in IT .”] is trained using historical operation shift reports including labeled modification records associated with a plurality of assets (Fig. 10, Fig. 4, Col 13 lines 10-55); and identify a first modification record [“ change request records are available 405” and “a context of the change request 410 (change request ticket, deployment or similar)”] from the first set of modification records using at least one correlation parameter, wherein the first modification record corresponds to the first asset; correlating the first modification with the modifications included in the first modification record to generate a correlation score [“ Calculate authorization score”] (Fig. 4, Col 10 lines 1- 20, claim 1); and an investigation engine [server 170’s CPU’s that detect type of changes (authorized in S342, unauthorized in S344, or potentially-authorized in S346) ] coupled to the analysis engine to:(Figs. 1, 3); compare [“ If authorization score exceeds the threshold, mark the change as authorized by change request record ”] the correlation score with a confidence value [“ the threshold ”] to verify the authenticity of the first modification; and generate a notification [“ mark the change as authorized ” or “potentially-authorized change” in S346 of fig. 3, “a context of the change request 410 (change request ticket, deployment or similar)” ] indicating the first modification to be authorized upon determining the correlation score to be above the confidence value (Col 10 lines 15- 30, Col 6 lines 5-15, Claim 1, Fig. 3). One may still argue that Kaluza may or may not teach “investigation” portion as required and hence cannot anticipate the claim. However, Pike teaches An unauthorized modification identification system (UMIS) [ system of fig. 1] comprising an investigation engine [ portion of management system 130 that receives “plurality of response messages from authorization devices of the multi-user authorization pool” ] coupled to the analysis engine to: verify the authenticity of the first modification made [“ plurality of response messages from authorization devices of the multi-user authorization pool ”] to the managed asset [ device 120 ]; and generate a notification indicating the first modification to be authorized (Fig. 1-2, [0119]). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to (1) combine Pike and Kaluza because they both related to an unauthorized modification identification system on the monitored assets and (2) modify the UMIS system of Kaluza to include an investigation function included CPU/engine to perform the comparing and generating a notification as in Pike. Doing so would allow to avoid unauthorized changes 344 taking effect in the monitored stations 110 and allow to recover from unauthorized changes that are already executed thereby bringing the changes into security compliance (Pike [017, 049]). Regarding claim 9, Kaluza in view of Pike teaches/suggests the UMIS of claim 8, wherein the at least one correlation parameter comprises at least one of the first asset identifier [“4 . A scope of the change, e.g. what parameters or elements will be changed and on which stations 110 of the environment ”] and a schedule [“1 . A start time of the change implementation; 2. An end time of the change implementation ”, “ the change time window is identified by appearing as a field in a change request record ”] of the first modification (Col 6 lines 40-55, claim 19). Regarding claim 10, Kaluza in view of Pike teaches/suggests the UMIS of claim 9, wherein the analysis engine is to further: obtain at least one second asset identifier [“ configuration parameters 150… firmware details, such as BIOS version , BIOS size and a checksum ”] corresponding to the first asset identifier; and utilize the at least one second asset identifier to identify the first modification record (Kaluza Col 5 lines 25-45, claim 1). Regarding claim 11, Kaluza in view of Pike teaches/suggests the UMIS of claim 8, wherein the first modification comprises a modification in operational configuration [“ collected information includes c onfiguration parameters 150 relating to the hardware and software installed in the stations 110 of IT system 100 ”] of the asset (Kaluza, Fig. 1, Claim 1, Col 4 lines 45-55). Regarding claim 12, Kaluza in view of Pike teaches/suggests the UMIS of claim 11, wherein the asset modification indication is received during an operation shift at the facility and the operation shift report corresponds to the operation shift (Kaluza Claim 1, Col 10 lines 25- 35). Regarding claim 13, Kaluza in view of Pike teaches/suggests the UMIS of claim 8, wherein the investigation engine is to transmit [“ an alert is transmitted ”] the notification indicating the first modification to be authorized to a Security Operations Center (SOC) [“ By providing alerts 174 to an administrator, e.g. to specific servers in the network or to mobile phones ;”] meant to monitor security related events for the facility (Kaluza, Fig. 1 & Pike Fig. 1, [018, 058]). Regarding claim 14, Kaluza in view of Pike teaches/suggests invention of this computer readable claim for the similar reasons set forth above in method and system claims 1 and 8. See Kaluza’s claim 20 for “computer readable medium”. Regarding claim 15, Kaluza in view of Pike teaches/suggests the non-transitory computer readable medium of claim 14, wherein the instructions further cause the processing resource to transmit a notification indicating the first modification to be unauthorized to a Security Operations Center (SOC) [“ By providing alerts 174 to an administrator, e.g. to specific servers in the network or to mobile phones” or “ transmit an alert /message to the management library 126 or to the management system 130 indicating that a change was detected. If the change is determined to be unauthorized , the management library 126 may revert any changes caused by the unapproved change. ”] meant to monitor security related events for the facility (Kaluza Fig. 1 & Pike Fig. 1, [058, 082]). Regarding claim 16, Kaluza in view of Pike teaches/suggests the non-transitory computer readable medium of claim 15, wherein the at least one correlation parameter comprises at least one of the first asset identifier [“ b) Identifying a scope of the content that was changed; c) Identifying a time window when the change was”] and a schedule [“authorized change maintenance time window ”] of the first modification (Kaluza Col 3 lines 35-55, Col 12 lines 35-55). Regarding claim 18, Kaluza in view of Pike teaches/suggests the non-transitory computer readable medium of claim 16, wherein to determine absence of the modification record corresponding to the first asset, the instructions cause the processing resource to: obtain at least one second asset identifier [e.g., “ names and sizes of files belonging to each application”] corresponding to the first asset identifier; and utilize the at least one second asset identifier to determine absence of the modification record corresponding to the first asset in the first set of modification records (Kaluza Col 3 lines 35-55, Col 5 lines 35-55). Regarding claim 18, Kaluza in view of Pike teaches/suggests the non-transitory computer readable medium of claim 15, wherein the asset modification indication is received during an operation shift at the facility and the operation shift report corresponds to the operation shift (Kaluza Col 10 lines 35-55). Regarding claim 19, Kaluza in view of Pike teaches/suggests the non-transitory computer readable medium of claim 15, wherein the first modification comprises a modification in operational configuration of the asset (Kaluza fig. 1, Col 5 lines 5-15). Regarding claim 20, Kaluza in view of Pike teaches/suggests the non-transitory computer readable medium of claim 19, wherein the instructions cause the processing resource to initiate a configuration restoration [“ may rollback the operating system 122 ”] operation for the asset, wherein the configuration restoration operation comprises rolling back the first modification (Pike [058]) . Conclusion 07-96 AIA The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. 1) Guedalia (US 20160300049 A1) teaches machine-learning behavioral analysis to detect device theft and unauthorized device usage (Abstract). 2) Mathur et al. (US 12293835 B1) teaches obtaining an operation shift report for the facility, wherein the operation shift report is indicative of modifications made to assets within the facility; analyzing the operation shift report [“ treatment authorization guidelines exist for the identified treatment ” ] using a natural language processing model [“a machine learning authorization process”, e.g., “identifying a natural language record processing model corresponding to the treatment authorization guidelines” ] to extract a first set of modification records associated with a first set of assets , wherein each of the first set of modification records comprises an asset identifier corresponding to an asset and modifications made to the asset, and the natural language processing model is trained [“ uses trained models to improve the time required to automate approvals ”] using historical operation shift reports including labeled modification records associated with a plurality of assets; identifying a first modification record in the first set of modification records using at least one correlation parameter, wherein the first modification record corresponds to the first asset (Col 2 lines 15-50, Col 3 lines 10-25). Contacts Any inquiry concerning this communication or earlier communications from the examiner should be directed to SANTOSH R. POUDEL whose telephone number is (571)272-2347. The examiner can normally be reached Monday - Friday (8:30 am - 5:00 pm). Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kamini Shah can be reached at (571) 272-2279. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /SANTOSH R POUDEL/ Primary Examiner, Art Unit 2115 Application/Control Number: 18/735,233 Page 2 Art Unit: 2115 Application/Control Number: 18/735,233 Page 3 Art Unit: 2115 Application/Control Number: 18/735,233 Page 4 Art Unit: 2115 Application/Control Number: 18/735,233 Page 5 Art Unit: 2115 Application/Control Number: 18/735,233 Page 6 Art Unit: 2115 Application/Control Number: 18/735,233 Page 7 Art Unit: 2115 Application/Control Number: 18/735,233 Page 8 Art Unit: 2115 Application/Control Number: 18/735,233 Page 9 Art Unit: 2115 Application/Control Number: 18/735,233 Page 10 Art Unit: 2115 Application/Control Number: 18/735,233 Page 11 Art Unit: 2115 Application/Control Number: 18/735,233 Page 12 Art Unit: 2115 Application/Control Number: 18/735,233 Page 13 Art Unit: 2115 Application/Control Number: 18/735,233 Page 14 Art Unit: 2115 Application/Control Number: 18/735,233 Page 15 Art Unit: 2115 Application/Control Number: 18/735,233 Page 16 Art Unit: 2115 Application/Control Number: 18/735,233 Page 17 Art Unit: 2115 1 “The functions of the various elements shown in the FIGs., including any functional blocks labelled as "processor(s)", may be provided through the use of dedicated hardware as well as hardware capable of executing instructions.”