Prosecution Insights
Last updated: October 02, 2026
Application No. 18/735,979

CONTINUOUS DATA CONTENT INTEGRITY COMPROMISE DETECTION

Final Rejection §103
Filed
Jun 06, 2024
Examiner
DILUZIO, NICHOLAS JOSEPH
Art Unit
2498
Tech Center
2400 — Computer Networks
Assignee
Dell Products L.P.
OA Round
2 (Final)
31%
Grant Probability
At Risk
3-4
OA Rounds
11m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants only 31% of cases
31%
Career Allowance Rate
5 granted / 16 resolved
-26.7% vs TC avg
Strong +83% interview lift
Without
With
+83.3%
Interview Lift
resolved cases with interview
Typical timeline
3y 2m
Avg Prosecution
24 currently pending
Career history
53
Total Applications
across all art units

Statute-Specific Performance

§101
10.5%
-29.5% vs TC avg
§103
66.3%
+26.3% vs TC avg
§102
6.2%
-33.8% vs TC avg
§112
17.0%
-23.0% vs TC avg
Black line = Tech Center average estimate • Based on career data from 16 resolved cases

Office Action

§103
DETAILED ACTION Examiner acknowledges receipt of Applicant’s amendment filed on 02/20/2026 Claims 1, 2, 5, 10-13, 16, and 20 are currently amended Claims 1-20 are pending Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Information Disclosure Statement The information disclosure statement (IDS) submitted on 05/20/2026 is in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner. Response to Amendment Examiner has fully considered Applicant’s amendments to the Claims in the arguments filed on 02/20/2026. Claims 1-20 remain pending in the application. Examiner has withdrawn the claim objections in view of the amendments. Response to Arguments Applicant’s arguments filed 02/20/2026, with respect to the rejections of independent claims 1 and 16 and their corresponding dependent claims under 35 USC 103 have been fully considered and are persuasive. Therefore, the rejections have been withdrawn. However, upon further consideration, new grounds of rejection are made in view of newly applied references from Natanzon et al. (US 10409986 B1), hereinafter Natanzon, and Sim-Tang (US 8060889 B2), hereinafter Sim-Tang. Examiner respectfully submits that the newly applied combination of Natanzon and Sim-Tang is sufficient to replace the previously relied upon teachings from Continella and Zachman at least with respect to the independent Claims 1 and 16. Specifically, the combination of Natanzon and Sim-Tang teaches the amended limitations “and wherein the detector operates on a server, wherein the server includes a memory and is configured to perform the detection operation on multiple IOs, consecutive IOs and non-consecutive IOs, wherein the detector specifies what is included in the data stream” in addition to the previously presented limitations. The newly applied Natanzon reference is also sufficient to replace the teachings from the previously applied Natanzon reference (US 10078459 B1). Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-4, 13, 16, and 18 is/are rejected under 35 U.S.C. 103 as being unpatentable over Natanzon et al. (US 10409986 B1), hereinafter Natanzon, in view of Sim-Tang (US 8060889 B2), hereinafter Sim-Tang. Regarding Claim 1: Natanzon teaches A method for performing protection in a computing system, the method comprising (Natanzon – Col. 1, Line 22-24: Described herein are embodiments of systems and methods for detecting and mitigating ransomware attacks in a continuous data protection environment): intercepting IOs (Input/Outputs) at an interceptor located in a data path (Natanzon – Col. 4, Line 51-55: hosts 104 and 116 include protection agents 144 and 164, respectively. Protection agents 144 and 164 are configured to intercept SCSI commands issued by their respective hosts to LUs via host devices (e.g. host devices 140 and 160); and Col. 5, Line 25-31: In certain embodiments, protection agents may be drivers located in their respective hosts. In other embodiments, a protection agent may be located in a fiber channel switch or in any other device situated in a data path between a host and a storage system or on the storage system itself In a virtualized environment, the protection agent may run at the hypervisor layer or in a virtual machine providing a virtualization layer), wherein the IOs are each associated with data and metadata (Natanzon – Col. 4, Line 3-7: In some embodiments, the I/O requests include SCSI commands. In many embodiments, an I/O request includes an address that includes a specific device identifier, an offset within the device, and a data size); transmitting a data stream based on the IOs to a detector in accordance with a transmission mode (Natanzon – Col. 4, Line 51-67, and Col. 5, Line 1-2: hosts 104 and 116 include protection agents 144 and 164, respectively. Protection agents 144 and 164 are configured to intercept SCSI commands issued by their respective hosts to LUs via host devices (e.g. host devices 140 and 160). A protection agent may act on an intercepted SCSI command issued to a logical unit, in one of the following ways: send the SCSI commands to its intended LU; redirect the SCSI command to another LU; split the SCSI command by sending it first to the respective DPA and, after the DPA returns an acknowledgement, send the SCSI command to its intended LU; fail a SCSI command by returning an error return code; and delay a SCSI command by not returning an acknowledgement to the respective host. A protection agent 144, 164 may handle different SCSI commands, differently, according to the type of the command. For example, a SCSI command inquiring about the size of a certain LU may be sent directly to that LU, whereas a SCSI write command may be split and sent first to a DPA within the host's site), wherein the detector performs a detection operation on the data stream (Natanzon – Col. 7, Line 52-60: the DPA 300 can be leveraged for the detection of potential ransomware within a host by analyzing I/O requests received from that host (or from a protection agent/splitter associated therewith). Specifically, the DPA's ransomware detection processor 304 is configured to analyze data written by a host, to determine whether write data is encrypted (i.e., “actually” encrypted), and to calculate the probability that ransomware is running on the host based upon this and other factors) and wherein the detector operates on a server, wherein the server includes a memory (Natanzon – Col. 4, Line 29-30: a DPA may be a standalone device integrated within a SAN (Storage area network); and Col. 10, Line 28-34: a computer 500 that can perform at least part of the processing described herein, according to one embodiment. The computer 500 may include a processor 502, a volatile memory 504, a non-volatile memory 506 (e.g., hard disk), an output device 508 and a graphical user interface (GUI) 510 (e.g., a mouse, a keyboard, a display, for example), each of which is coupled together by a bus 518) and is configured to perform the detection operation on multiple IOs (Natanzon – Col. 7, Line 52-67, and Col. 8, Line 1-2: the DPA 300 can be leveraged for the detection of potential ransomware within a host by analyzing I/O requests received from that host (or from a protection agent/splitter associated therewith). Specifically, the DPA's ransomware detection processor 304 is configured to analyze data written by a host, to determine whether write data is encrypted (i.e., “actually” encrypted), and to calculate the probability that ransomware is running on the host based upon this and other factors … In some embodiments, when processing an I/O write request, the ransomware detection processor looks at only data within that write to determine whether it is encrypted. In other embodiments, the ransomware detection processor keeps a history of recent write data and performs an encryption analysis over the recent history (e.g., by calculating the entropy of the last N write requests)), consecutive IOs and non-consecutive IOs (Natanzon – Col. 7, Line 52-67, and Col. 8, Line 1-2: the DPA 300 can be leveraged for the detection of potential ransomware within a host by analyzing I/O requests received from that host (or from a protection agent/splitter associated therewith). Specifically, the DPA's ransomware detection processor 304 is configured to analyze data written by a host, to determine whether write data is encrypted (i.e., “actually” encrypted), and to calculate the probability that ransomware is running on the host based upon this and other factors … In some embodiments, when processing an I/O write request, the ransomware detection processor looks at only data within that write to determine whether it is encrypted. In other embodiments, the ransomware detection processor keeps a history of recent write data and performs an encryption analysis over the recent history (e.g., by calculating the entropy of the last N write requests); and Col. 4, Line 51-67, and Col. 5, Line 1-2: hosts 104 and 116 include protection agents 144 and 164, respectively. Protection agents 144 and 164 are configured to intercept SCSI commands issued by their respective hosts to LUs via host devices (e.g. host devices 140 and 160). A protection agent may act on an intercepted SCSI command issued to a logical unit, in one of the following ways: send the SCSI commands to its intended LU; redirect the SCSI command to another LU; split the SCSI command by sending it first to the respective DPA and, after the DPA returns an acknowledgement, send the SCSI command to its intended LU; fail a SCSI command by returning an error return code; and delay a SCSI command by not returning an acknowledgement to the respective host. A protection agent 144, 164 may handle different SCSI commands, differently, according to the type of the command. For example, a SCSI command inquiring about the size of a certain LU may be sent directly to that LU, whereas a SCSI write command may be split and sent first to a DPA within the host's site; Examiner’s Comment: The cited teaching demonstrates a capability for the DPA to perform the detection operation on either consecutive or non-consecutive IOs. Because the protection agent handles different types of SCSI commands differently (e.g. an inquiry is sent directly to the LU while a write is split to the DPA), the writes received by the DPA may or may not represent consecutive IOs); receiving a response from the detector; and performing an action on the IOs in the data path based on the response (Natanzon – Col. 8, Line 28-62: if the ransomware probability exceeds one or more predetermined thresholds, then the DPA 300 may take actions to mitigate the effects of a potential ransomware attack … In some embodiments, the first mitigation action includes creating a bookmark. In such embodiments, if a user confirms that the data was actually infected by ransomware, the user call rollback the state of storage to the point in time when the bookmark was created, thereby mitigating the impact of the ransomware attack. In some embodiments, creating a bookmark includes adding metadata to the journal associated with a given point in time. In certain embodiments, the second mitigation action includes delaying host writes to the storage array. As discussed above in conjunction with FIG. 1, in some embodiments when a splitter receives a write from a host, it may send the write to a DPA, wait for an acknowledgement (ACK) from the DPA, and then send the write to the storage array after receiving the ACK. Thus, in some embodiments, the DPA can slow down writes to the storage array by delaying ACKs to the splitter, thereby reducing the number of files that may be affected by a suspected ransomware attack. In some embodiments, the second mitigation includes notifying a user of the suspected ransomware to determine whether an actual ransomware attack has occurred and, if so, whether to rollback to a bookmarked point in time). Natanzon does not expressly teach wherein the detector specifies what is included in the data stream. However, Sim-Tang teaches wherein the detector specifies what is included in the data stream (Sim-Tang – Col. 7, Line 2-4: a given DMS host driver uses an I/O filter to intercept data events between an application and its primary data storage; and Col. 7, Line 16-24: the host driver 500 in a host server connects to one of the DMS nodes in a DMS cluster (in a DMS region) to perform or facilitate a data service. The host driver preferably includes two logical subsystems, namely, an I/O filter 502, and at least one data agent 504. An illustrative data agent 504 preferably includes one or more modules, namely, an application module 506, a database module 508, an I/O module 510, and an event processor or event processing engine 512; and Col. 7, Line 61-63: The I/O module 510 instructs the I/O filter 502 to capture a set of one or more I/O events that are of interest to the data agent; and Col. 9, Line 28-40: Because the application module, the database module and the I/O filter capture data and events in real-time continuously, as these raw events are processed the host driver outputs an event journal comprising a stream of outbound application aware, real-time information … Real-time event journaling in this manner captures fine grain and consistent data changes for data protection in the DMS; and Col. 10, Line 20-47: Generalizing, the I/O filter captures file system events or block device I/O events according to the configuration from the data agents. Preferably, a data agent instructs the I/O filter both on what events to watch and how the filter should behave when the event arrives … Based on the needs of a data agent at a given time, an I/O module 802 of the data agent registers a filtering request 804 with an I/O filter 806. This filtering request typically has two parameters, a data path and a filter table 808. The data path instructs the I/O filter 806 as to the data scope it should cover, and the filter table 808 instructs the I/O filter 806 what events it should filter and how). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Natanzon, further incorporating Sim-Tang to arrive at the claimed invention. Sim-Tang teaches a data management system (DMS) that provides a range of data services including data protection. The DMS facilitates the data protection services by deploying one or more host drivers to monitor and collect data transactions between applications and their associated primary storage(s). A host driver includes at least an I/O filter and a data agent. The I/O filter intercepts I/O events (e.g., file/block reads and writes) in accordance with instructions provided by the data agent that receives the intercepted events. The selectively filtered data enables the system to collect particular event data on particular data paths based to capture fine-grained data changes based on system preferences. This capability for custom configuration of an I/O filter combines naturally with the protection agent and DPA taught by Natanzon. That is, combining Sim-Tang’s known technique for configuring an I/O filter to intercept selected events on selected data paths within a system with Natanzon’s process for splitting SCSI commands to a DPA to perform ransomware detection operations produces the obvious benefit of selective interception and transmission of I/O information to the DPA for subsequent analysis. The resulting combination would allow Natanzon’s protection agent to provide the DPA with information particularly relevant for ransomware detection. Thus, in view of KSR, it would have been obvious to a person having ordinary skill in the art to combine Natanzon and Sim-Tang. Regarding Claim 2: The combination of Natanzon and Sim-Tang teaches the method of Claim 1. Natanzon further teaches further comprising generating the data stream from the intercepted IOs, wherein the data stream includes metadata of the intercepted IOs and/or data of the intercepted IOs (Natanzon – Col. 4, Line 3-7: In some embodiments, the I/O requests include SCSI commands. In many embodiments, an I/O request includes an address that includes a specific device identifier, an offset within the device, and a data size; and Col. 6, Line 64-67 and Col. 7, Line 1-2: The write transaction 200 includes one or more identifiers; a time stamp indicating the date and time at which the transaction was received by the source DPA; a write size indicating the size of the data block; a location in the journal LU where the data is entered; a location in the target LU where the data is to be written; and the data itself). The motivation to combine the arts is the same as that of Claim 1. Regarding Claim 3: The combination of Natanzon and Sim-Tang teaches the method of Claim 1. Natanzon further teaches wherein the data stream includes one or more of, for the IOs, metadata including a target, location, and a length, a hash of the data, a filename, an object identifier, access information, a timestamp, a counter, or combinations thereof (Natanzon – Col. 4, Line 3-7: In some embodiments, the I/O requests include SCSI commands. In many embodiments, an I/O request includes an address that includes a specific device identifier, an offset within the device, and a data size; and Col. 6, Line 64-67 and Col. 7, Line 1-2: The write transaction 200 includes one or more identifiers; a time stamp indicating the date and time at which the transaction was received by the source DPA; a write size indicating the size of the data block; a location in the journal LU where the data is entered; a location in the target LU where the data is to be written; and the data itself). The motivation to combine the arts is the same as that of Claim 1. Regarding Claim 4: The combination of Natanzon and Sim-Tang teaches the method of Claim 1. Sim-Tang further teaches further comprising generating the data stream by filtering the IOs based on target, target location, time, and/or expression such that the data stream includes filtered data (Sim-Tang – Col. 10, Line 24-38: For example, in a file system example, a data agent may instruct an I/O filter to watch for successful post-file-open (file-opened) event of a specific path and, when the event occurs, to gather the user information and queue the event along with the information. (A successful post-file-open event is when a file is successfully opened in the primary file system storage). As another example, the data agent may also instruct the I/O filter to capture a pre-file-open event of a specific directory scope, queue the event, and block the primary I/O until the event is processed. (A pre-file-open event is an open-file request from an application that is not yet processed by the primary file system). As another example, the data agent may further instruct the I/O filter to ignore some subset of events of a specific directory scope, or a specific device volume). The motivation to combine the arts is the same as that of Claim 1. Regarding Claim 13: The combination of Natanzon and Sim-Tang teaches the method of Claim 1. Natanzon further teaches wherein the interceptor is installed in one of a user space of an operating system, a kernel space of the operating system, in an accelerator card, in a smart network interface card, in a virtual machine, in a hypervisor, in a container host, in cloud infrastructure, in a storage array, in a network, or in a switch (Natanzon – Col. 5, Line 25-32: In certain embodiments, protection agents may be drivers located in their respective hosts. In other embodiments, a protection agent may be located in a fiber channel switch or in any other device situated in a data path between a host and a storage system or on the storage system itself In a virtualized environment, the protection agent may run at the hypervisor layer or in a virtual machine providing a virtualization layer). The motivation to combine the arts is the same as that of Claim 1. Regarding Claim 16: Natanzon teaches A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations for protecting a computing system, the operations comprising (Natanzon – Col. 1, Line 66-67 and Col. 2, Line 1-4: According to another aspect of the disclosure, a system comprises one or more processors; a volatile memory; and a non-volatile memory storing computer program code that when executed on the processor causes execution across the one or more processors of a process operable to perform embodiments of the method described hereinabove): intercepting IOs (Input/Outputs) at an interceptor located in a data path (Natanzon – Col. 4, Line 51-55: hosts 104 and 116 include protection agents 144 and 164, respectively. Protection agents 144 and 164 are configured to intercept SCSI commands issued by their respective hosts to LUs via host devices (e.g. host devices 140 and 160); and Col. 5, Line 25-31: In certain embodiments, protection agents may be drivers located in their respective hosts. In other embodiments, a protection agent may be located in a fiber channel switch or in any other device situated in a data path between a host and a storage system or on the storage system itself In a virtualized environment, the protection agent may run at the hypervisor layer or in a virtual machine providing a virtualization layer), wherein the IOs are each associated with data and metadata (Natanzon – Col. 4, Line 3-7: In some embodiments, the I/O requests include SCSI commands. In many embodiments, an I/O request includes an address that includes a specific device identifier, an offset within the device, and a data size); transmitting a data stream based on the IOs to a detector in accordance with a transmission mode (Natanzon – Col. 4, Line 51-67, and Col. 5, Line 1-2: hosts 104 and 116 include protection agents 144 and 164, respectively. Protection agents 144 and 164 are configured to intercept SCSI commands issued by their respective hosts to LUs via host devices (e.g. host devices 140 and 160). A protection agent may act on an intercepted SCSI command issued to a logical unit, in one of the following ways: send the SCSI commands to its intended LU; redirect the SCSI command to another LU; split the SCSI command by sending it first to the respective DPA and, after the DPA returns an acknowledgement, send the SCSI command to its intended LU; fail a SCSI command by returning an error return code; and delay a SCSI command by not returning an acknowledgement to the respective host. A protection agent 144, 164 may handle different SCSI commands, differently, according to the type of the command. For example, a SCSI command inquiring about the size of a certain LU may be sent directly to that LU, whereas a SCSI write command may be split and sent first to a DPA within the host's site), wherein the detector performs a detection operation on the data stream (Natanzon – Col. 7, Line 52-60: the DPA 300 can be leveraged for the detection of potential ransomware within a host by analyzing I/O requests received from that host (or from a protection agent/splitter associated therewith). Specifically, the DPA's ransomware detection processor 304 is configured to analyze data written by a host, to determine whether write data is encrypted (i.e., “actually” encrypted), and to calculate the probability that ransomware is running on the host based upon this and other factors) and wherein the detector operates on a server, wherein the server includes a memory (Natanzon – Col. 4, Line 29-30: a DPA may be a standalone device integrated within a SAN (Storage area network); and Col. 10, Line 28-34: a computer 500 that can perform at least part of the processing described herein, according to one embodiment. The computer 500 may include a processor 502, a volatile memory 504, a non-volatile memory 506 (e.g., hard disk), an output device 508 and a graphical user interface (GUI) 510 (e.g., a mouse, a keyboard, a display, for example), each of which is coupled together by a bus 518) and is configured to perform the detection operation on multiple IOs (Natanzon – Col. 7, Line 52-67, and Col. 8, Line 1-2: the DPA 300 can be leveraged for the detection of potential ransomware within a host by analyzing I/O requests received from that host (or from a protection agent/splitter associated therewith). Specifically, the DPA's ransomware detection processor 304 is configured to analyze data written by a host, to determine whether write data is encrypted (i.e., “actually” encrypted), and to calculate the probability that ransomware is running on the host based upon this and other factors … In some embodiments, when processing an I/O write request, the ransomware detection processor looks at only data within that write to determine whether it is encrypted. In other embodiments, the ransomware detection processor keeps a history of recent write data and performs an encryption analysis over the recent history (e.g., by calculating the entropy of the last N write requests)), consecutive IOs and non-consecutive IOs (Natanzon – Col. 7, Line 52-67, and Col. 8, Line 1-2: the DPA 300 can be leveraged for the detection of potential ransomware within a host by analyzing I/O requests received from that host (or from a protection agent/splitter associated therewith). Specifically, the DPA's ransomware detection processor 304 is configured to analyze data written by a host, to determine whether write data is encrypted (i.e., “actually” encrypted), and to calculate the probability that ransomware is running on the host based upon this and other factors … In some embodiments, when processing an I/O write request, the ransomware detection processor looks at only data within that write to determine whether it is encrypted. In other embodiments, the ransomware detection processor keeps a history of recent write data and performs an encryption analysis over the recent history (e.g., by calculating the entropy of the last N write requests); and Col. 4, Line 51-67, and Col. 5, Line 1-2: hosts 104 and 116 include protection agents 144 and 164, respectively. Protection agents 144 and 164 are configured to intercept SCSI commands issued by their respective hosts to LUs via host devices (e.g. host devices 140 and 160). A protection agent may act on an intercepted SCSI command issued to a logical unit, in one of the following ways: send the SCSI commands to its intended LU; redirect the SCSI command to another LU; split the SCSI command by sending it first to the respective DPA and, after the DPA returns an acknowledgement, send the SCSI command to its intended LU; fail a SCSI command by returning an error return code; and delay a SCSI command by not returning an acknowledgement to the respective host. A protection agent 144, 164 may handle different SCSI commands, differently, according to the type of the command. For example, a SCSI command inquiring about the size of a certain LU may be sent directly to that LU, whereas a SCSI write command may be split and sent first to a DPA within the host's site; Examiner’s Comment: The cited teachings demonstrate a capability for the DPA to perform the detection operation on either consecutive or non-consecutive IOs. Because the protection agent handles different types of SCSI commands differently (e.g. an inquiry is sent directly to the LU while a write is split to the DPA), the writes received by the DPA may or may not represent consecutive IOs); receiving a response from the detector; and performing an action on the IOs in the data path based on the response (Natanzon – Col. 8, Line 28-62: if the ransomware probability exceeds one or more predetermined thresholds, then the DPA 300 may take actions to mitigate the effects of a potential ransomware attack … In some embodiments, the first mitigation action includes creating a bookmark. In such embodiments, if a user confirms that the data was actually infected by ransomware, the user call rollback the state of storage to the point in time when the bookmark was created, thereby mitigating the impact of the ransomware attack. In some embodiments, creating a bookmark includes adding metadata to the journal associated with a given point in time. In certain embodiments, the second mitigation action includes delaying host writes to the storage array. As discussed above in conjunction with FIG. 1, in some embodiments when a splitter receives a write from a host, it may send the write to a DPA, wait for an acknowledgement (ACK) from the DPA, and then send the write to the storage array after receiving the ACK. Thus, in some embodiments, the DPA can slow down writes to the storage array by delaying ACKs to the splitter, thereby reducing the number of files that may be affected by a suspected ransomware attack. In some embodiments, the second mitigation includes notifying a user of the suspected ransomware to determine whether an actual ransomware attack has occurred and, if so, whether to rollback to a bookmarked point in time). Natanzon does not expressly teach wherein the detector specifies what is included in the data stream. However, Sim-Tang teaches wherein the detector specifies what is included in the data stream (Sim-Tang – Col. 7, Line 2-4: a given DMS host driver uses an I/O filter to intercept data events between an application and its primary data storage; and Col. 7, Line 16-24: the host driver 500 in a host server connects to one of the DMS nodes in a DMS cluster (in a DMS region) to perform or facilitate a data service. The host driver preferably includes two logical subsystems, namely, an I/O filter 502, and at least one data agent 504. An illustrative data agent 504 preferably includes one or more modules, namely, an application module 506, a database module 508, an I/O module 510, and an event processor or event processing engine 512; and Col. 7, Line 61-63: The I/O module 510 instructs the I/O filter 502 to capture a set of one or more I/O events that are of interest to the data agent; and Col. 9, Line 28-40: Because the application module, the database module and the I/O filter capture data and events in real-time continuously, as these raw events are processed the host driver outputs an event journal comprising a stream of outbound application aware, real-time information … Real-time event journaling in this manner captures fine grain and consistent data changes for data protection in the DMS; and Col. 10, Line 20-47: Generalizing, the I/O filter captures file system events or block device I/O events according to the configuration from the data agents. Preferably, a data agent instructs the I/O filter both on what events to watch and how the filter should behave when the event arrives … Based on the needs of a data agent at a given time, an I/O module 802 of the data agent registers a filtering request 804 with an I/O filter 806. This filtering request typically has two parameters, a data path and a filter table 808. The data path instructs the I/O filter 806 as to the data scope it should cover, and the filter table 808 instructs the I/O filter 806 what events it should filter and how). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Natanzon, further incorporating Sim-Tang to arrive at the claimed invention. Sim-Tang teaches a data management system (DMS) that provides a range of data services including data protection. The DMS facilitates the data protection services by deploying one or more host drivers to monitor and collect data transactions between applications and their associated primary storage(s). A host driver includes at least an I/O filter and a data agent. The I/O filter intercepts I/O events (e.g., file/block reads and writes) in accordance with instructions provided by the data agent that receives the intercepted events. The selectively filtered data enables the system to collect particular event data on particular data paths based to capture fine-grained data changes based on system preferences. This capability for custom configuration of an I/O filter combines naturally with the protection agent and DPA taught by Natanzon. That is, combining Sim-Tang’s known technique for configuring an I/O filter to intercept selected events on selected data paths within a system with Natanzon’s process for splitting SCSI commands to a DPA to perform ransomware detection operations produces the obvious benefit of selective interception and transmission of I/O information to the DPA for subsequent analysis. The resulting combination would allow Natanzon’s protection agent to provide the DPA with information particularly relevant for ransomware detection. Thus, in view of KSR, it would have been obvious to a person having ordinary skill in the art to combine Natanzon and Sim-Tang. Regarding Claim 18: The combination of Natanzon and Sim-Tang teaches the non-transitory storage medium of claim 16. Sim-Tang further teaches further comprising generating the data stream by filtering the IO based on location, time, and/or expression and/or generating the data stream by sampling the IO based on time or in a statistical manner (Sim-Tang – Col. 10, Line 24-38: For example, in a file system example, a data agent may instruct an I/O filter to watch for successful post-file-open (file-opened) event of a specific path and, when the event occurs, to gather the user information and queue the event along with the information. (A successful post-file-open event is when a file is successfully opened in the primary file system storage). As another example, the data agent may also instruct the I/O filter to capture a pre-file-open event of a specific directory scope, queue the event, and block the primary I/O until the event is processed. (A pre-file-open event is an open-file request from an application that is not yet processed by the primary file system). As another example, the data agent may further instruct the I/O filter to ignore some subset of events of a specific directory scope, or a specific device volume). The motivation to combine the arts is the same as that of Claim 16. Claim(s) 5 is/are rejected under 35 U.S.C. 103 as being unpatentable over Natanzon in view of Sim-Tang and Continella et al. (US 20180157834 A1), hereinafter Continella. Regarding Claim 5: The combination of Natanzon and Sim-Tang teaches the method of Claim 1. The combination of Natanzon and Sim-Tang does not expressly teach further comprising generating the data stream by sampling the IOs based on time or in a statistical manner such that the data stream includes samples from the intercepted IOs. However, Continella teaches further comprising generating the data stream by sampling the IO based on time or in a statistical manner such that the data stream includes samples from the intercepted IOs (Continella – Paragraph [0106]-[0108]: The protection method comprises at least the following steps: [0107] intercepting I/O request packets (IRPs) from a filesystem layer of an operating system; [0108] automatic detection of ransomware activities as a function of said intercepted IRPs and based on the combined analysis of predefined filesystem-activity features; and Paragraph [0112]: Particularly, the protection method comprises at least a step of preliminary scanning for collecting the statistics of the filesystem, and at least a step of updating said statistics of the filesystem, executed in real time or periodically). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Natanzon and Sim-Tang, further incorporating Continella to arrive at the claimed invention. One would be motivated to incorporate Continella’s teaching to periodically scan intercepted I/O requests into Natanzon and Sim-Tang’s data monitoring for storage system protection. This additional consideration provides a system behavior baseline for comparison in detecting potentially malicious behavior. Claim(s) 6 and 8-10 is/are rejected under 35 U.S.C. 103 as being unpatentable over Natanzon in view of Sim-Tang and Zachman et al. (US 20070174910 A1), hereinafter Zachman. Regarding Claim 6: The combination of Natanzon and Sim-Tang teaches the method of Claim 1. The combination of Natanzon and Sim-Tang does not expressly teach further comprising setting the transmission mode to a synchronous mode, an asynchronous mode, or an out of band mode. However, Zachman teaches further comprising setting the transmission mode to a synchronous mode, an asynchronous mode, or an out of band mode (Zachman – Paragraph [0021]: In one example, the MSP may interact in-band (within the standard bus mechanism) with computer executive program, operating system modules and computer applications to provide security and application isolation features, or ultimately as a CPU logic component for the same purposes; and Paragraph [0022]: In another example, the MSP may protect data, application, security and executive software operations through side-band (within a new invention-to-memory mechanism) memory processing, monitoring and access-protection activities; and Paragraph [0023]: In another example, the MSP may provide out-of-band (outside of the standard bus mechanism) security management operations using a mobile security component and an existing communication bus, or a new management bus ("SafeBus")). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Natanzon and Sim-Tang, further incorporating Zachman to arrive at the claimed invention. One would be motivated to incorporate Zachman’s teaching of various selectable transmission modes into Natanzon and Sim-Tang’s data monitoring for storage system protection. This combined functionality provides configurable settings for data protection modes aligning with particular security conditions. Regarding Claim 8: The combination of Natanzon, Sim-Tang, and Zachman teaches the method of claim 6. Zachman further teaches wherein the detector has full control over the IOs in the synchronous mode, wherein the detection operation is completed and acknowledged before the IOs are allowed to proceed to a target (Zachman – Paragraph [0073]: FIG. 3 is a high-level block diagram illustrating an exemplary MSP Security Controller 7 shown intercepting memory I/O requests as the memory I/O requests flow between CPU 2 and a memory module within system memory 8. The example shows an embodiment in which MSP Security Controller 7 includes a plurality of Security Blades 22 that provide security operations on the memory I/O request as the request flows from the CPU 2 to the memory module (and back), as well as security operations directly on memory itself, independent of the individual memory I/O request; and Paragraph [0074]: As a memory I/O request flows across the plurality of Security Blades 22 on a path of the memory I/O request to the memory, MSP processor 24 reviews, monitors, checks, transforms or blocks the memory I/O request at each stage of the stack of Security Blades 22 as directed by security settings. In other words, MSP processor 24 uses Security Blades 22 to determine whether the memory I/O request constitutes a security threat. If MSP processor 24 determines that the memory I/O request does not constitute a security threat, MSP processor 24 allows the memory I/O request to be performed. Security Blades 22 are shown inline for simplicity of illustration, but the MSP Security Controller 7 may process the Blade operations serially or in parallel as security conditions warrant). The motivation to combine the arts is the same as that of Claim 6. Regarding Claim 9: The combination of Natanzon, Sim-Tang, and Zachman teaches the method of claim 6. Zachman further teaches wherein the detector has partial control over the IO in the asynchronous mode, wherein the detection operation and transmission of the IOs to the target and the detector are performed in parallel (Zachman – Paragraph [0089]: In some exemplary embodiments, MSP Security Controller 7 includes a plurality of parallel Event Engines 34, each with the ability to view a stream of memory transactions as the transactions would normally occur at real-time system speed; and Paragraph [0156]: Embodiments of the MSP make use of special hardware circuitry that offers memory security operations in parallel with existing memory connections. The design allows CPU/Northbridge and DMA operations to access the memory modules without outside contention from the MSP. This is a unique MSP design that provides memory monitoring and access without adding contention problems plagued by standard PCI hardware or other security solutions). The motivation to combine the arts is the same as that of Claim 6. Regarding Claim 10: The combination of Natanzon, Sim-Tang, and Zachman teaches the method of claim 6. Zachman further teaches wherein the IOs are transmitted out of band in the out of band mode (Zachman – Paragraph [0023]: In another example, the MSP may provide out-of-band (outside of the standard bus mechanism) security management operations using a mobile security component and an existing communication bus, or a new management bus ("SafeBus"); and Paragraph [0175]: By utilizing the out-of-band SSI control conduit, the MSP can remote monitoring, logging and overall security information to an outside command center for global management purposes). The motivation to combine the arts is the same as that of Claim 6. Regarding Claim 11: The combination of Natanzon, Sim-Tang, and Zachman teaches the method of claim 10. Natanzon further teaches wherein a collator is configured to collate at least some of the IOs for transmission to the detector (Natanzon – Col. 6, Line 35-43: In batch mode, the source DPA 112 may receive several I/O requests and combines them into an aggregate “batch” of write activity performed in the multiple I/O requests, and may send the batch to the target DPA 124, for journaling and for incorporation in target storage system 120. In batch mode, the source DPA 112 may send an acknowledgement to protection agent 144 upon receipt of each I/O request, before receiving an acknowledgement back from the target DPA 124). Zachman further teaches in the out of band mode (Paragraph [0023]: In another example, the MSP may provide out-of-band (outside of the standard bus mechanism) security management operations using a mobile security component and an existing communication bus, or a new management bus ("SafeBus")). The motivation to combine the arts is the same as that of Claim 10. Claim(s) 7 is/are rejected under 35 U.S.C. 103 as being unpatentable over Natanzon in view of Sim-Tang, Zachman, Cassar (Cassar, I., & Francalanza, A. (2015). On synchronous and asynchronous monitor instrumentation for actor-based systems. Electronic Proceedings in Theoretical Computer Science, 175, 54–68. https://doi.org/10.4204/eptcs.175.4), hereinafter Cassar, and Fortunato (Fortunato, T. (2016, April 15). SPAN port vs. TAP: The latency impact. NetworkComputing. https://www.networkcomputing.com/network-infrastructure/span-port-vs-tap-the-latency-impact), hereinafter Fortunato. Regarding Claim 7: The combination of Natanzon, Sim-Tang, and Zachman teaches the method of claim 6. The combination of Natanzon, Sim-Tang, and Zachman does not expressly teach wherein the synchronous mode, the asynchronous mode, and the out of band mode are associated with different latencies and wherein latency can be controlled by changing the mode. However, Cassar teaches wherein the synchronous mode, the asynchronous mode[, and the out of band mode] are associated with different latencies and wherein latency can be controlled by changing the mode (Cassar – P. 62: The graphs obtained in Fig. 6 clearly show that synchronous monitoring incurs higher overheads than its asynchronous counterpart in terms of CPU Utilisation, memory consumption and the latencies it introduces). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Natanzon, Sim-Tang, and Zachman, further incorporating Cassar to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Cassar’s attribution of different degrees of latency with regard to synchronous and asynchronous monitoring techniques into Natanzon, Sim-Tang, and Zachman’s method for protecting a computing system. This addition further highlights the tradeoffs between security and transmission efficiency in selecting a mode for I/O monitoring. The combination of Natanzon, Sim-Tang, Zachman, and Cassar does not expressly teach wherein the … out of band mode … associated with different latencies and wherein latency can be controlled by changing the mode. However, Fortunato teaches wherein [the synchronous mode,] the asynchronous mode, and the out of band mode are associated with different latencies and wherein latency can be controlled by changing the mode (Fortunato – P. 4: The test results show that a SPAN port created more latency between the packets and additional latency when a packet was received. In conclusion, you should be aware of your SPAN port limitations and where TAPs might complement your toolbox). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Natanzon, Sim-Tang, Zachman, and Cassar, further incorporating Fortunato to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Fortunato’s attribution of different degrees of latency with regard to asynchronous and out-of-band monitoring techniques into Natanzon, Sim-Tang, Zachman, and Cassar’s method for protecting a computing system. Coupled with Cassar’s teachings, Fortunato’s demonstration that out-of-band monitoring (TAP) creates less latency than asynchronous monitoring (SPAN), would provide a user with more context in selecting a transmission mode based on system/user preferences. Claim(s) 12 is/are rejected under 35 U.S.C. 103 as being unpatentable over Natanzon in view of Sim-Tang and Sallam (US 20120255021 A1), hereinafter Sallam. Regarding Claim 12: The combination of Natanzon and Sim-Tang teaches the method of Claim 1. The combination of Natanzon and Sim-Tang does not expressly teach further comprising intercepting the IOs with a second interceptor positioned at a different location of the data path. However, Sallam teaches further comprising intercepting the IOs with a second interceptor positioned at a different location of the data path (Sallam – Figure 9: illustration of a system for securing an I/O path between an application and an I/O device, in which I/O operations are intercepted twice along the path). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Natanzon and Sim-Tang, further incorporating Sallam to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Sallam’s multiple I/O interception-points into Natanzon and Sim-Tang’s method for protecting a computing system. This combination would enhance the security of the system by adding at least another checkpoint to ensure transmissions were not tampered with along the path. Claim(s) 14 and 20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Natanzon in view of Sim-Tang, Porras (US 20140007184 A1), hereinafter Porras, and Inbaraj et al. (US 20180359184 A1), hereinafter Inbaraj. Regarding Claim 14: The combination of Natanzon and Sim-Tang teaches the method of Claim 1. The combination of Natanzon and Sim-Tang does not expressly teach wherein the interceptor includes a telemetry interface for transmitting the data stream. However, Zachman teaches wherein the interceptor includes a telemetry interface for transmitting the data stream (Zachman – Paragraph [0081]: Security Manager 26 is a base logical component of MSP Security Controller 7, and represents the main component that interacts with and provides an interface to ISO Module 9). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Natanzon and Sim-Tang, further incorporating Zachman to arrive at the claimed invention. One would be motivated to incorporate Zachman’s telemetry interface for an interceptor into Natanzon and Sim-Tang’s data monitoring for storage system protection. This addition practically enables communication between the interceptor and the detector. The combination of Natanzon, Sim-Tang, and Zachman does not expressly teach a control interface configured to receive a response from the detector. However, Porras teaches a control interface configured to receive a response from the detector (Porras – Paragraph [0009]: The data flow policy engine may be configured to evaluate system calls made by the instances of security-wrapped software applications by interfacing with an access interceptor of each of the security-wrapped software applications; and Paragraph [0024]: In operation, an executing application 112 may initiate a data access request by a variety of different means, such as any type of input/output (I/O) command. As noted above, the access interceptor/policy enforcer 114 operates at the system call level, and intercepts system calls that pertain to data access requests, prior to their execution by the mobile device 102; and Paragraph [0025]: Upon intercepting a system call corresponding to a data access request, the access interceptor/policy enforcer 114 communicates the access request to the data flow policy engine 106. In turn, the data flow policy engine 106 determines whether the intercepted access request conforms to one or more of the data flow policies contained in the policies kb 110, and communicates a corresponding policy decision to the access interceptor/policy enforcer 114 without otherwise affecting the operation of the application 112). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Natanzon, Sim-Tang, and Zachman, further incorporating Porras to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Porras’s demonstration of direct communication between an interceptor and detector into Natanzon, Sim-Tang, and Zachman’s method for protecting a computing system. This addition further provides practical means for enabling communication between system components toward system protection. The combination of Natanzon, Sim-Tang, Zachman, and Porras does not expressly teach and a subscription interface. However, Inbaraj teaches and a subscription interface (Inbaraj – Paragraph [0031]: The subscription component 222 provides a subscription service of the telemetry application 143. The telemetry application 143 of the telemetry subscriber device 140 may send an inquiry to the subscription component 222 to obtain information regarding the telemetry data 250 available for subscription at the telemetry service 136. Based on the response from the telemetry service 136, the telemetry application 143 may subscribe to the telemetry service 136 for receiving certain subsets of the telemetry data 250 of the host computer 180 from the telemetry service 136). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Natanzon, Sim-Tang, Zachman, and Porras, further incorporating Inbaraj to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Inbaraj’s selectable subscription for certain telemetry data forwarding/monitoring into Natanzon, Sim-Tang, Zachman, and Porras’s method for protecting a computing system. The combined functionality allows further user-customizability of the system for more directed security and analysis. Regarding Claim 20: The combination of Natanzon and Sim-Tang teaches the non-transitory storage medium of claim 16. Natanzon further teaches wherein the interceptor is installed in one of a user space of an operating system, a kernel space of the operating system, in an accelerator card, in a smart network interface card, in a virtual machine, in a hypervisor, in a container host, in cloud infrastructure, in a storage array, in a network, or in a switch (Natanzon – Col. 5, Line 25-32: In certain embodiments, protection agents may be drivers located in their respective hosts. In other embodiments, a protection agent may be located in a fiber channel switch or in any other device situated in a data path between a host and a storage system or on the storage system itself In a virtualized environment, the protection agent may run at the hypervisor layer or in a virtual machine providing a virtualization layer). The combination of Natanzon and Sim-Tang does not expressly teach wherein the interceptor includes a telemetry interface for transmitting the data stream. However, Zachman teaches wherein the interceptor includes a telemetry interface for transmitting the data stream (Zachman – Paragraph [0081]: Security Manager 26 is a base logical component of MSP Security Controller 7, and represents the main component that interacts with and provides an interface to ISO Module 9). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Natanzon and Sim-Tang, further incorporating Zachman to arrive at the claimed invention. One would be motivated to incorporate Zachman’s telemetry interface for an interceptor into Natanzon and Sim-Tang’s data monitoring for storage system protection. This addition practically enables communication between the interceptor and the detector. The combination of Natanzon, Sim-Tang, and Zachman does not expressly teach a control interface configured to receive a response from the detector … wherein the interceptor is configured to act as a response tool in response to the response from the detector, wherein the response may include an instruction to block some or all IOs, filter out IOS or types of IOs, delay IOs, and/or redirect IOs to a sink hole or quarantine. However, Porras teaches a control interface configured to receive a response from the detector (Porras – Paragraph [0009]: The data flow policy engine may be configured to evaluate system calls made by the instances of security-wrapped software applications by interfacing with an access interceptor of each of the security-wrapped software applications; and Paragraph [0024]: In operation, an executing application 112 may initiate a data access request by a variety of different means, such as any type of input/output (I/O) command. As noted above, the access interceptor/policy enforcer 114 operates at the system call level, and intercepts system calls that pertain to data access requests, prior to their execution by the mobile device 102; and Paragraph [0025]: Upon intercepting a system call corresponding to a data access request, the access interceptor/policy enforcer 114 communicates the access request to the data flow policy engine 106. In turn, the data flow policy engine 106 determines whether the intercepted access request conforms to one or more of the data flow policies contained in the policies kb 110, and communicates a corresponding policy decision to the access interceptor/policy enforcer 114 without otherwise affecting the operation of the application 112) … wherein the interceptor is configured to act as a response tool in response to the response from the detector, wherein the response may include an instruction to block some or all IOs, filter out IOS or types of IOs, delay IOs, and/or redirect IOs to a sink hole or quarantine (Paragraph [0024]: In operation, an executing application 112 may initiate a data access request by a variety of different means, such as any type of input/output (I/O) command. As noted above, the access interceptor/policy enforcer 114 operates at the system call level, and intercepts system calls that pertain to data access requests, prior to their execution by the mobile device 102; and Paragraph [0025]: Upon intercepting a system call corresponding to a data access request, the access interceptor/policy enforcer 114 communicates the access request to the data flow policy engine 106. In turn, the data flow policy engine 106 determines whether the intercepted access request conforms to one or more of the data flow policies contained in the policies kb 110, and communicates a corresponding policy decision to the access interceptor/policy enforcer 114 without otherwise affecting the operation of the application 112; and Paragraph [0030]: A policy decision may take the form of, e.g., one or more instructions, arguments and/or parameters that are passed back or otherwise made available to the access interceptor/policy enforcer 114. As noted above, the access interceptor/policy enforcer 114 determines what, if anything, the subject 104 should do in response to the policy decision, and issues an access decision back to the executing application 112 as needed. The access decision may take the form of, e.g., an instruction, argument and/or parameter that is passed back or otherwise made available to the application 112. The access decision may result in the application 112 executing the access request and continuing normal operation, ignoring the access request and continuing normal execution, suspending execution (e.g., to wait for user feedback), or closing, for example). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Natanzon, Sim-Tang, and Zachman, further incorporating Porras to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Porras’s interceptor as a response tool to act in response to a detection made by a detector into Natanzon, Sim-Tang, and Zachman’s method for protecting a computing system. This combination provides the system with the capability for direct action on the data path when it is determined that an anomalous I/O has occurred. The combination of Natanzon, Sim-Tang, Zachman, and Porras does not expressly teach and a subscription interface. However, Inbaraj teaches and a subscription interface (Inbaraj – Paragraph [0031]: The subscription component 222 provides a subscription service of the telemetry application 143. The telemetry application 143 of the telemetry subscriber device 140 may send an inquiry to the subscription component 222 to obtain information regarding the telemetry data 250 available for subscription at the telemetry service 136. Based on the response from the telemetry service 136, the telemetry application 143 may subscribe to the telemetry service 136 for receiving certain subsets of the telemetry data 250 of the host computer 180 from the telemetry service 136). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Natanzon, Sim-Tang, Zachman, and Porras, further incorporating Inbaraj to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Inbaraj’s selectable subscription for certain telemetry data forwarding/monitoring into Natanzon, Sim-Tang, Zachman, and Porras’s method for protecting a computing system. The combined functionality further allows further user-customizability of the system for more directed security and analysis. Claim(s) 15 is/are rejected under 35 U.S.C. 103 as being unpatentable over Natanzon in view of Sim-Tang and Porras. Regarding Claim 15: The combination of Natanzon and Sim-Tang teaches the method of Claim 1. The combination of Natanzon and Sim-Tang does not expressly teach wherein the interceptor is configured to act as a response tool in response to the response from the detector, wherein the response may include an instruction to block some or all IOs, filter out IOs or types of IOs, delay IOs, and/or redirect IOs to a sink hole or quarantine. However, Porras teaches wherein the interceptor is configured to act as a response tool in response to the response from the detector, wherein the response may include an instruction to block some or all IOs, filter out IOS or types of IOs, delay IOs, and/or redirect IOs to a sink hole or quarantine (Paragraph [0024]: In operation, an executing application 112 may initiate a data access request by a variety of different means, such as any type of input/output (I/O) command. As noted above, the access interceptor/policy enforcer 114 operates at the system call level, and intercepts system calls that pertain to data access requests, prior to their execution by the mobile device 102; and Paragraph [0025]: Upon intercepting a system call corresponding to a data access request, the access interceptor/policy enforcer 114 communicates the access request to the data flow policy engine 106. In turn, the data flow policy engine 106 determines whether the intercepted access request conforms to one or more of the data flow policies contained in the policies kb 110, and communicates a corresponding policy decision to the access interceptor/policy enforcer 114 without otherwise affecting the operation of the application 112; and Paragraph [0030]: A policy decision may take the form of, e.g., one or more instructions, arguments and/or parameters that are passed back or otherwise made available to the access interceptor/policy enforcer 114. As noted above, the access interceptor/policy enforcer 114 determines what, if anything, the subject 104 should do in response to the policy decision, and issues an access decision back to the executing application 112 as needed. The access decision may take the form of, e.g., an instruction, argument and/or parameter that is passed back or otherwise made available to the application 112. The access decision may result in the application 112 executing the access request and continuing normal operation, ignoring the access request and continuing normal execution, suspending execution (e.g., to wait for user feedback), or closing, for example). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Natanzon and Sim-Tang, further incorporating Porras to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Porras’s interceptor as a response tool to act in response to a detection made by a detector into Natanzon and Sim-Tang’s method for protecting a computing system. This combination provides the system with the capability for direct action on the data path when it is determined that an anomalous I/O has occurred. Claim(s) 19 is/are rejected under 35 U.S.C. 103 as being unpatentable over Natanzon in view of Sim-Tang, Zachman, Cassar, and Fortunato. Regarding Claim 19: The combination of Natanzon and Sim-Tang teaches the non-transitory storage medium of claim 16. Natanzon further teaches wherein a collator is configured to collate multiple IOs for transmission to the detector [in the out of band mode] (Natanzon – Col. 6, Line 35-43: In batch mode, the source DPA 112 may receive several I/O requests and combines them into an aggregate “batch” of write activity performed in the multiple I/O requests, and may send the batch to the target DPA 124, for journaling and for incorporation in target storage system 120. In batch mode, the source DPA 112 may send an acknowledgement to protection agent 144 upon receipt of each I/O request, before receiving an acknowledgement back from the target DPA 124). The combination of Natanzon and Sim-Tang does not expressly teach setting the transmission mode to a synchronous mode, an asynchronous mode, or an out of band mode; wherein the detector has full control over the IO in the synchronous mode, wherein the detection operation is completed and acknowledged before the IO is allowed to proceed to a target in the synchronous mode; wherein the detector has partial control over the IO in the asynchronous mode, wherein the detection operation and transmission of the IOs to the target and the detector are performed in parallel; and wherein the IO is transmitted out of band in the out of band mode; and in the out of band mode. However, Zachman further teaches setting the transmission mode to a synchronous mode, an asynchronous mode, or an out of band mode (Zachman – Paragraph [0021]: In one example, the MSP may interact in-band (within the standard bus mechanism) with computer executive program, operating system modules and computer applications to provide security and application isolation features, or ultimately as a CPU logic component for the same purposes; and Paragraph [0022]: In another example, the MSP may protect data, application, security and executive software operations through side-band (within a new invention-to-memory mechanism) memory processing, monitoring and access-protection activities; and Paragraph [0023]: In another example, the MSP may provide out-of-band (outside of the standard bus mechanism) security management operations using a mobile security component and an existing communication bus, or a new management bus ("SafeBus")); wherein the detector has full control over the IO in the synchronous mode, wherein the detection operation is completed and acknowledged before the IO is allowed to proceed to a target in the synchronous mode (Zachman – Paragraph [0073]: FIG. 3 is a high-level block diagram illustrating an exemplary MSP Security Controller 7 shown intercepting memory I/O requests as the memory I/O requests flow between CPU 2 and a memory module within system memory 8. The example shows an embodiment in which MSP Security Controller 7 includes a plurality of Security Blades 22 that provide security operations on the memory I/O request as the request flows from the CPU 2 to the memory module (and back), as well as security operations directly on memory itself, independent of the individual memory I/O request; and Paragraph [0074]: As a memory I/O request flows across the plurality of Security Blades 22 on a path of the memory I/O request to the memory, MSP processor 24 reviews, monitors, checks, transforms or blocks the memory I/O request at each stage of the stack of Security Blades 22 as directed by security settings. In other words, MSP processor 24 uses Security Blades 22 to determine whether the memory I/O request constitutes a security threat. If MSP processor 24 determines that the memory I/O request does not constitute a security threat, MSP processor 24 allows the memory I/O request to be performed. Security Blades 22 are shown inline for simplicity of illustration, but the MSP Security Controller 7 may process the Blade operations serially or in parallel as security conditions warrant); wherein the detector has partial control over the IO in the asynchronous mode, wherein the detection operation and transmission of the IOs to the target and the detector are performed in parallel (Zachman – Paragraph [0089]: In some exemplary embodiments, MSP Security Controller 7 includes a plurality of parallel Event Engines 34, each with the ability to view a stream of memory transactions as the transactions would normally occur at real-time system speed; and Paragraph [0156]: Embodiments of the MSP make use of special hardware circuitry that offers memory security operations in parallel with existing memory connections. The design allows CPU/Northbridge and DMA operations to access the memory modules without outside contention from the MSP. This is a unique MSP design that provides memory monitoring and access without adding contention problems plagued by standard PCI hardware or other security solutions); and wherein the IO is transmitted out of band in the out of band mode (Zachman – Paragraph [0023]: In another example, the MSP may provide out-of-band (outside of the standard bus mechanism) security management operations using a mobile security component and an existing communication bus, or a new management bus ("SafeBus"); and Paragraph [0175]: By utilizing the out-of-band SSI control conduit, the MSP can remote monitoring, logging and overall security information to an outside command center for global management purposes); and in the out of band mode (Zachman – Paragraph [0023]: In another example, the MSP may provide out-of-band (outside of the standard bus mechanism) security management operations using a mobile security component and an existing communication bus, or a new management bus ("SafeBus"); and Paragraph [0175]: By utilizing the out-of-band SSI control conduit, the MSP can remote monitoring, logging and overall security information to an outside command center for global management purposes). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Natanzon and Sim-Tang, further incorporating Zachman to arrive at the claimed invention. One would be motivated to incorporate Zachman’s teaching of various selectable transmission modes into Natanzon and Sim-Tang’s data monitoring for storage system protection. This combined functionality provides configurable settings for data protection modes aligning with particular security conditions. The combination of Natanzon, Sim-Tang, and Zachman does not expressly teach wherein the synchronous mode has a first latency, the asynchronous mode has a second latency[, and the out of band mode has a third latency,] wherein: [third latency <] second latency < first latency. However, Cassar teaches wherein the synchronous mode has a first latency, the asynchronous mode has a second latency[, and the out of band mode has a third latency,] wherein: [third latency <] second latency < first latency (Cassar – P. 62: The graphs obtained in Fig. 6 clearly show that synchronous monitoring incurs higher overheads than its asynchronous counterpart in terms of CPU Utilisation, memory consumption and the latencies it introduces). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Natanzon, Sim-Tang, and Zachman, further incorporating Cassar to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Cassar’s attribution of different degrees of latency with regard to synchronous and asynchronous monitoring techniques into Natanzon, Sim-Tang, and Zachman’s method for protecting a computing system. This addition further highlights the tradeoffs between security and transmission efficiency in selecting a mode for I/O monitoring. The combination of Natanzon, Sim-Tang, Zachman, and Cassar does not expressly teach wherein [the synchronous mode has a first latency,] the asynchronous mode has a second latency, and the out of band mode has a third latency, wherein: third latency < second latency [< first latency]. However, Fortunato teaches wherein [the synchronous mode has a first latency,] the asynchronous mode has a second latency, and the out of band mode has a third latency, wherein: third latency < second latency [< first latency] (Fortunato – P. 4: The test results show that a SPAN port created more latency between the packets and additional latency when a packet was received. In conclusion, you should be aware of your SPAN port limitations and where TAPs might complement your toolbox). It would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to modify Natanzon, Sim-Tang, Zachman, and Cassar, further incorporating Fortunato to arrive at the conclusion of the claimed invention. One would be motivated to incorporate Fortunato’s attribution of different degrees of latency with regard to asynchronous and out-of-band monitoring techniques into Natanzon, Sim-Tang, Zachman, and Cassar’s method for protecting a computing system. Coupled with Cassar’s teachings, Fortunato’s demonstration that out-of-band monitoring (TAP) creates less latency than asynchronous monitoring (SPAN), would provide a user with more context in selecting a transmission mode based on system/user preferences. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Dar et al. (US 20240176882 A1) teaches techniques for IO stream sampling to facilitate ML-based detection of malware/ransomware Raskin et al. (US 20150058975 A1) teaches methods for selectively capturing traffic between a host and a connected device toward detection of potentially malicious behavior Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to NICHOLAS JOSEPH DILUZIO whose telephone number is (703)756-1229. The examiner can normally be reached Mon - Fri -- 7:30 AM - 5 PM. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Yin-Chen Shaw can be reached at 571-272-8878. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /NICHOLAS JOSEPH DILUZIO/Examiner, Art Unit 2498 /YIN CHEN SHAW/Supervisory Patent Examiner, Art Unit 2498
Read full office action

Prosecution Timeline

Jun 06, 2024
Application Filed
Nov 20, 2025
Non-Final Rejection mailed — §103
Feb 20, 2026
Response Filed
Sep 11, 2026
Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12596792
DATA ENCRYPTION DETECTION
4y 0m to grant Granted Apr 07, 2026
Patent 12490087
AUTHENTICATION SERVER FUNCTION SELECTION IN AN AUTHENTICATION AND KEY AGREEMENT
3y 6m to grant Granted Dec 02, 2025
Patent 12475218
METHOD AND SYSTEM FOR IDENTIFYING A COMPROMISED POINT-OF-SALE TERMINAL NETWORK
3y 0m to grant Granted Nov 18, 2025
Patent 12367440
ARTIFICIAL INTELLIGENCE-BASED SYSTEM AND METHOD FOR FACILITATING MANAGEMENT OF THREATS FOR AN ORGANIZATON
2y 11m to grant Granted Jul 22, 2025
Patent 11966466
UNIFIED WORKLOAD RUNTIME PROTECTION
2y 3m to grant Granted Apr 23, 2024
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
31%
Grant Probability
99%
With Interview (+83.3%)
3y 2m (~11m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 16 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month