DETAILED ACTION
Status of Application: Claims 1-13 are present for examination at this time.
Claims 1, and 8-9 are rejected.
Please refer to Forms 892 of record in this application and/or submitted IDSes to resolve any possible discrepancies in the listed reference numbers, titles, and/or author or inventor names.
Applicant is reminded that claim mapping is provided as a courtesy to the applicant, but applicant should consider a reference as a whole, as the entire reference gives context to mapped sections.
Notice of Pre-AIA AIA Status
The present application, filed on after March 16, 2013, is being examined under the first invent to file provisions of the AIA .
Restriction/Election
Examiner notes Applicant’s election without traverse on 7/9/2026 of Claims 1, 8, and 9.
Claim Rejections 35 U.S.C. 102
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale or otherwise available to the public before the effective filing date of the claimed invention.
(a)(2) the claimed invention was described in a patent issued under section 151, or in an application for patent published or deemed published under section 122(b), in which the patent or application, as the case may be, names another inventor and was effectively filed before the effective filing date of the claimed invention.
Claims 1, 8, and 9 are rejected under 35 U.S.C. 102(a) (2) as being anticipated by “Detection Of Periodic Transmissions For Identifying Malicious Computers” by Luo et al, US11,063,969 (“Luo”)
PNG
media_image1.png
754
582
media_image1.png
Greyscale
With respect to Claim 1, Luo discloses a malicious communication detection device comprising: a processor to execute a program; and a memory to store the program which, when executed by the processor, performs processes (Luo 1:38-41, 7:39-54)
acquiring a communication message and determining whether the communication message is a normal message on the basis of a periodicity requirement set for each of time-varying states of the communication message, (Luo 3:1-47 where a message is received, and it’s periodicity is used to determined if the message is an attack).
wherein the periodicity requirement of the communication message is identified on the basis of a state of the communication message classified according to a transition type which is a factor affecting a periodic error of the communication message and a plurality of transition conditions which is set for each transition type to determine whether the communication message is a normal message (Id., 5:66-6:10, and 6:53-7:11 where the periodicity is gauged mathematically, and if the periodicity is within or outside a specified range, the message is determined to be malicious or safe).
With respect to Claim 8, Luo discloses a malicious communication detection method comprising:
acquiring a communication message; and determining whether the communication message is a normal message on the basis of a periodicity requirement set for each time-varying state of the communication message, (Luo 3:1-47 where a message is received, and it’s periodicity is used to determined if the message is an attack).
wherein in the determining, the periodicity requirement of the communication message is identified on the basis of a state of the communication message classified according to a transition type which is a factor affecting a periodic error of the communication message and a plurality of transition conditions which is set for each transition type, and it is determined whether the communication message is a normal message (Id., 5:66-6:10, and 6:53-7:11 where the periodicity is gauged mathematically, and if the periodicity is within or outside a specified range, the message is determined to be malicious or safe).
With respect to Claim 9, Luo discloses a storage medium storing a malicious communication detection program for causing a computer to perform all of the processing according to claim 8 (Luo at 7:55-64, “An article of manufacture may be embodied as computer-readable storage medium including instructions that when executed by the processor 101 cause the network security device 100 to be operable to perform the functions of the one or more software modules 110” )
Claims 1, 8, and 9 are rejected under 35 U.S.C. 102(a) (2) as being anticipated by “Periodicity Detection Of Network Traffic” by Reed et al., US10,671,708B2
With respect to Claim 1, Reed discloses a malicious communication detection device comprising: a processor to execute a program; and a memory to store the program which, when executed by the processor, performs processes (Hitachi ¶¶31-39)
acquiring a communication message and determining whether the communication message is a normal message on the basis of a periodicity requirement set for each of time-varying states of the communication message, (Reed at 1:38-2:3 where a message is received, and it’s periodicity is used to determined if the message is an attack).
wherein the periodicity requirement of the communication message is identified on the basis of a state of the communication message classified according to a transition type which is a factor affecting a periodic error of the communication message and a plurality of transition conditions which is set for each transition type to determine whether the communication message is a normal message (Reed 3:1-16 and 4:9-23 where the periodicity is gauged mathematically, and if the periodicity is within or outside a specified range, the message is determined to be malicious or safe)
With respect to Claim 8, Reed discloses a malicious communication detection method comprising:
acquiring a communication message; and determining whether the communication message is a normal message on the basis of a periodicity requirement set for each time-varying state of the communication message, (Reed at 1:38-2:3 where a message is received, and it’s periodicity is used to determined if the message is an attack).
wherein in the determining, the periodicity requirement of the communication message is identified on the basis of a state of the communication message classified according to a transition type which is a factor affecting a periodic error of the communication message and a plurality of transition conditions which is set for each transition type, and it is determined whether the communication message is a normal message (Reed 3:1-16 and 4:9-23 where the periodicity is gauged mathematically, and if the periodicity is within or outside a specified range, the message is determined to be malicious or safe)
With respect to Claim 9, Reed discloses a storage medium storing a malicious communication detection program for causing a computer to perform all of the processing according to claim 8 Reed 2:4-11 “Examples are implemented as a computer process, a computing system, or as an article of manufacture such as a device, computer program product, or computer readable medium. According to an aspect, the computer program product is a computer storage medium readable by a computer system and encoding a computer program comprising instructions for executing a computer process.” )
Claims 1, 8, and 9 are rejected under 35 U.S.C. 102(a) (2) as being anticipated by “Information Processing Device and Authorized Communication Determination Method” WO2021/024786A1 (“Hitachi”)
With respect to Claim 1, Hitachi discloses a malicious communication detection device comprising: a processor to execute a program; and a memory to store the program which, when executed by the processor, performs processes (Hitachi ¶¶31-39)
acquiring a communication message and determining whether the communication message is a normal message on the basis of a periodicity requirement set for each of time-varying states of the communication message, (Hitachi ¶¶31-33 where a message is received, and it’s periodicity is used to determined if the message is an attack).
wherein the periodicity requirement of the communication message is identified on the basis of a state of the communication message classified according to a transition type which is a factor affecting a periodic error of the communication message and a plurality of transition conditions which is set for each transition type to determine whether the communication message is a normal message (Hitachi ¶¶37-39 where the periodicity is gauged mathematically, and if the periodicity is within or outside a specified range, the message is determined to be malicious or safe)
With respect to Claim 8, Hitachi discloses a malicious communication detection method comprising:
acquiring a communication message; and determining whether the communication message is a normal message on the basis of a periodicity requirement set for each time-varying state of the communication message, (Hitachi ¶¶31-33 where a message is received, and it’s periodicity is used to determined if the message is an attack).
wherein in the determining, the periodicity requirement of the communication message is identified on the basis of a state of the communication message classified according to a transition type which is a factor affecting a periodic error of the communication message and a plurality of transition conditions which is set for each transition type, and it is determined whether the communication message is a normal message (Hitachi ¶¶37-39 where the periodicity is gauged mathematically, and if the periodicity is within or outside a specified range, the message is determined to be malicious or safe).
With respect to Claim 9, Hitachi discloses a storage medium storing a malicious communication detection program for causing a computer to perform all of the processing according to claim 8 (Hitachi at ¶19 “The program source may be, for example, a program distribution server or a storage medium readable by a computer.” )
Documents Considered but not relied upon
The following references read substantially if not completely on Claim 1.
CYBERSECURITY ON A CONTROLLER AREA NETWORK IN A VEHICLE US20210203682 (discusses detecting intrusions based on patterns that are periodic at ¶¶14, 16, and 23)
ATTACK DETECTION APPARATUS, ATTACK DETECTION METHOD AND PROGRAM US 20230247035 A1 (discusses at ¶¶8-10 using periodicity to detect attacks, but needing to account for false positives.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to JOSHUA L SCHWARTZ whose telephone number is (571)270-7494. The examiner can normally be reached on M-F 10a-6p.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, Applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Yuwen “Kevin” Pan at 571-272-7855. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/JOSHUA L SCHWARTZ/Primary Examiner, Art Unit 2649