Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
Currently pending claims are 1 – 20.
Response to Arguments
Applicant's arguments with respect to instant claims have been fully considered but are moot in view of the new ground(s) of rejection necessitated by Applicant's amendment – please see the following section for the detail of rationale to make the corresponding prior-art(s) rejections as set forth below.
As per claim 1, Applicant asserts prior-art(s) does not teach the newly added claim element such as to “create all necessary SIEM artifacts for the data connector specific to the tenant server” (Remarks: Page 9). Examiner respectfully disagrees with the following rationale.
(a) Examiner notes according to MPEP 2111 of the broadest and reasonable claim interpretations, applicant’s argument has no merit since the alleged limitation such as “exactly what is the complete coverage of all necessary SIEM artifacts in its meaning and its content” has not been specifically recited into the claim. Although the claims are interpreted in light of the specification, limitations from the specification are not read into the claims. See In re Van Geuns, 988 F.2d 1181, 26 USPQ2d 1057 (Fed. Cir. 1993).
(b) In light of that, Rostami et al. (WO 2017/151515 A1) teaches artifact information can be imported into a SIEM tool (i.e. security information and event management tool) to enable the SIEM management application to generate SIEM artifacts – for example, if the artifacts are determined to be associated with malware based on the automated malware analysis, then the artifact can be deemed a high-risk artifact to be informed to the various log sources (Rostami: Para [0276] / [0275]). As such Applicant's arguments are respectfully traversed.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION. The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claims 1, 11 & 19 are rejected under 35 U.S.C. 112(b) or 35 U.S.C. 112 (pre-AIA ), second paragraph, as being indefinite for failing to particularly point out and distinctly claim the subject matter which the inventor or a joint inventor (or for applications subject to pre-AIA 35 U.S.C. 112, the applicant), regards as the invention because the claim language “create all necessary SIEM artifacts for the data connector specific to the tenant server” is considered to be unclear and indefinite when reciting the claim by using the word “all necessary SIEM artifacts” regarding:
(a) exactly what are the complete coverage of all necessary SIEM artifacts in its meaning and its content and besides,
(b) there is no specific indications throughout the entire disclosure of the instant specification regarding exactly what are the all necessary SIEM artifacts – As such Examiner respectfully notes the precise metes and bound of the claim, as alleged, cannot be determined. See § MPEP 2173.05(b). Any other claims not addressed are rejected by virtue of their dependency should also be corrected.
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the exclaimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1 – 20 are rejected under 35 U.S.C.103 as being unpatentable over Cristofi et al. (U.S. Patent 2021/0117251), in view of Milazzo et al. (U.S. Patent 2020/0186569), and in view of Rostami et al. (WO 2017/151515 A1).
As per claim 1 & 19, Cristofi teaches a method of enhancing network security, the method comprising:
providing a Security Information, and Event Management (SIEM) management application configured to be hosted by a SIEM provider server (Cristofi: Figure 17, Para [1006] / [1015], and para [1017]: (a) an IT and security operations application ingests data from a SIEM system (Cristofi: Figure 17 & Para [1015]) that constitutes a part of SIEM management application), wherein (b) the SIEM management application is hosted on a provider network comprising various network provider severs (server computing systems) that includes, at least, a SIEM provider server and a tenant (customer) provider server), wherein the SIEM provider server is communicably coupled to a tenant server (Cristofi: see above & Figure 17 / E-1736 and Para [1004] / [1006] / 1023] / [1107] / [1017]: coupling to multi-tenant database servers);
coupling, via a data connector, the SIEM management application to a log source hosted by the tenant server (Cristofi: see above & FIG.23 / E-2306, E-1702, FIG.17, Para [1008] / [1015] / [0123] / [1053] and Para [1017]: using a tunnel bridge (i.e. a data connector) to communicate between the SIEM management application (i.e. IT and security operations application) and a data source of IT assets (i.e. one type of log sources) hosted by a tenant server of a tenant network), wherein the data connector is configured the control a flow of data to and from the log source (Cristofi: see above & Para [1051] – [1053] and Para [1090]: the tunnel bridge (i.e. a data connector) is a cloud-based service configured to transfer data between an IT and security operations application (i.e. a SIEM management application) and various data sources of IT assets (i.e. one type of log sources) via established secure communication channels such as to control a flow of data to and from a target log source accordingly);
generating, via the SIEM management application, a JavaScript Object Notation (JSON) based solution bundle for the log source (Cristofi: see above & Para [0258] / [0254] / [0647] / [0531] / [0647] and Para [1008]: the SIEM management application, as a part of the data intake and query system (DIQS) intake point, generates data records by an HTTP intake point configured to be formatted as JavaScript Object Notation, or JSON messages (i.e. a JSON based solution bundle), the data records being obtained from various data sources of IT assets (i.e. one type of log sources)), wherein the JSON based solution bundle is configured to, upon deployment, create all necessary SIEM artifacts for the data connector specific to the tenant server (Cristofi: see above & Para [0193] Last sentence: (a) hosting a SIEM management application on a provider network that comprises various network provider severs such as a SIEM provider server and a tenant server and (b) providing system flexibility and scalability in a distributed cloud-based environment such that upon deployment of the data records such as the JSON based solution bundle included in the data intake and query system (DIQS) associated with the SIEM management application, additional computer resources can be further deployed for processing) ||
(Rostami: Para [0276] / [0275]: the additional computer resources such as the artifact information can be imported into a SIEM tool (i.e. security information and event management tool) to enable the SIEM management application to generate SIEM artifacts – for example, if the artifacts are determined to be associated with malware based on the automated malware analysis, then the artifact can be deemed a high-risk artifact to be informed to the various log sources).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention was made to propose the modification of, upon deployment, creating all necessary SIEM artifacts for the data connector specific to the tenant server, wherein the SIEM artifacts because Rostami teaches to alternatively, effectively and securely provide a comprehensive security mechanism by importing the artifact(s) into a security information and event management (SIEM) tools to enable the SIEM management application to generate SIEM artifacts (see above) within the Cristofi’s system of (a) hosting a SIEM management application on a provider network that comprises various network provider severs such as a SIEM provider server and a tenant server and (b) providing system flexibility and scalability in a distributed cloud-based environment such that upon deployment of the data records such as the JSON based solution bundle included in the data intake and query system (DIQS) associated with the SIEM management application, additional computer resources can be further deployed for processing (see above).
wherein the SIEM artifacts comprises at least one of a resource group, a log analytics workspace, a data connector, an alert rule, a playbook. or a workbook for the tenant server (Cristofi: see above & Para [0647] / [0258]: communicating "data records" from ingestion buffers with JSON messages as a JSON blobs (i.e. a small lump / collection) as a JSON-based bundle and the data record can include, at least, a resource group such as data associated with a particular tenant or a reference to a location (e.g. physical or logical directory, file name, etc.) that stores the data associated with the tenant that is to be processed by the indexing system).
However, Cristofi does not disclose expressly generating a proposed SIEM protocol, wherein the proposed SIEM protocol is based, at least in part, on the JSON-based solution bundle.
Milazzo (& Cristofi) teaches generating a proposed SIEM protocol, wherein the proposed SIEM protocol is based, at least in part, on the JSON-based solution bundle (Cristofi: see above & Para [0647] / [0258]) || ((Milazzo: Para [0078] / [0057] & FIG. 1):
(a) First of all, the term of "protocol" generally means a set of procedures for what actions to take in a certain situation for specific uses; and
(b) In light of that, Milazzo teaches generating / providing / proposing a SIEM rule query that involves evaluation and communication of various "data records" from different sources associated with a specific use of SIEM rule management system along with a SIEM database / data-store (Milazzo: Para [0078] / [0057] & FIG. 1) – this can be construed as one type of "SIEM protocols"; and besides,
(b) Cristofi teaches communicating the "data records" from ingestion buffers with JSON messages as a JSON blobs (i.e. a small lump / collection) as a JSON-based bundle and the data record can include, at least, a resource group (Cristofi: Para [0647] / [0258]). Accordingly, in view of (a) & (b), a combination of Cristofi & Milazzo indeed teaches generating a proposed SIEM protocol, wherein the proposed SIEM protocol is based, at least in part, on the JSON-based solution bundle such as to govern how the data connector controls the flow of data to and from the log source (i.e. database or data-store) to meet the claim language.
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention was made to propose the modification of deploying, via the SIEM management application, a proposed SIEM protocol from the SIEM provider server to the tenant server because Milazzo teaches to alternatively, effectively and securely provide a comprehensive security mechanism by generating and deploying a SIEM rule / protocol (Security Information & Event Management) to be used by security monitoring engines at customer (i.e. tenant) monitored computing environments hosted by various tenant servers to improve security monitoring capability (see above) within the Cristofi’s system of hosting a SIEM management application on a provider network that comprises various network provider severs such as a SIEM provider server and a tenant (customer) provider server (see above).
wherein the proposed SIEM protocol defines deployment variables for the tenant server comprising at least one of a subscription, a resource group, a workspace, or a log source derived from the JSON-based solution bundle (Cristofi: see above & Para [0647] / [0258]: communicating "data records" from ingestion buffers with JSON messages as a JSON blobs (i.e. a small lump / collection) as a JSON-based bundle and the data record can include, at least, a resource group such as data associated with a particular tenant or a reference to a location (e.g. physical or logical directory, file name, etc.) that stores the data associated with the tenant that is to be processed by the indexing system); and
deploying, via the SIEM management application, the proposed SIEM protocol from the SIEM provider server to the tenant server (Cristofi: see above) || (Milazzo: FIG. 1 & Para [0078] / [0057] Line 22 – 25 / Para [0023]: providing (proposing) an automated mechanism for generating and deploying a SIEM rule / protocol (Security Information & Event Management) to be used by security monitoring engines at customer (i.e. tenant) monitored computing environments hosted by various tenant servers to improve security monitoring capability), wherein the proposed SIEM protocol is configured to govern how the data connector controls the flow of data to and from the log source (Cristofi: see above & Para [1051] – [1053] and Para [1090]: a tunnel bridge (i.e. a data connector) is a cloud-based service configured to transfer data between an IT and security operations application (i.e. a SIEM management application) and various data sources of IT assets (i.e. one type of log sources) via established secure communication channels such as to control a flow of data to and from a target log source accordingly) || (Milazzo: Para [0078] / [0057] & FIG. 1: generating / providing / proposing a SIEM rule query that involves evaluation and communication of various "data records" from different sources associated with a specific use of SIEM rule management system along with a SIEM database / data-store).
As per claim 11, the claim limitations are met as the same reasons as that set forth in the paragraph above regarding to claim 1 with the exception of the feature(s) of:
a Security Information, and Event Management (SIEM) provider server communicably coupled to the tenant server and the display (Cristofi: see above, FIG. 22 & Para [0902] / [1014] and Para [0531] / [0532]: (a) allowing the administrator / user to see a visualization display of related events via a user interface, wherein (b) IT and security operations application (i.e. SIEM management application) displaying information related to an occurrence of an incident (event) in an IT environment such as executable actions for responding to the incident as part of a workbook that is generated based on the identified incident).
As per claim 2 – 5, 12 – 15 & 20, Rostami (& Cristofi as modified) teaches generating, via the SIEM management application, at least one of a plurality of SIEM artifacts (Cristofi: see above) || (Rostami: Para [0276] / [0275]: the artifact information can be imported into a SIEM tool (i.e. security information and event management tool) to enable the SIEM management application to generate SIEM artifacts – for example, if the artifacts are determined to be associated with malware based on the automated malware analysis, then the artifact can be deemed a high-risk artifact to be informed to the various log sources).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention was made to propose the modification of generating, via the SIEM management application, at least one of a plurality of SIEM artifacts because Rostami teaches to alternatively, effectively and securely provide a comprehensive security mechanism by importing the artifact(s) into a security information and event management (SIEM) tools to enable the SIEM management application to generate SIEM artifacts (see above) within the Cristofi’s system of hosting a SIEM management application on a provider network that comprises various network provider severs such as a SIEM provider server and a tenant (customer) provider server (see above).
As per claim 6 & 16, Rostami (& Cristofi as modified) teaches configuring alert rules to govern how the data connector controls the flow of data to and from the log source (Cristofi: see above) || (Rostami: Para [0057]: the alert rule to generate an alert can be (e.g., for a customer/subscriber of the platform) when there is a matching tag, and there is network traffic for that sample in the monitored network (e.g., the subscriber’s enterprise network, or for an alert if the tag is triggered based on a public sample that was detected in another subscriber’s enterprise network, such as another subscriber that is in a same industry category).
As per claim 7 & 17, Cristofi as modified teaches wherein the proposed SIEM protocol for the tenant server is a first proposed SIEM protocol of a plurality of proposed SIEM protocols generated based, at least in part, on the JSON-based solution bundle, and wherein the method further comprises visually displaying, via a user interface of the SIEM management application, the plurality of proposed SIEM protocols (Cristofi: see above, FIG. 22 & Para [0902] / [1014] and Para [0531] / [0532]: visually displaying, via a user interface of the SIEM management application, a proposed SIEM protocol for the tenant server based on the JSON-based solution bundle (based on the results represented in JSON format, providing recommendations based on users of the same tenant (a proposed SIEM protocol), allowing the administrator to see a visualization (displaying) of related events via user interface).
As per claim 8 & 18, Cristofi as modified teaches deploying the proposed SIEM protocol from the SIEM provider server to the tenant server is based, at least in part, on a user selection of the proposed SIEM protocol from the plurality of proposed SIEM protocols (Milazzo: see above & Para [0023] & [0057] Line 22 – 25: (a) the ingested information that is collected can be based on user-specific (i.e. user-definable / selectable) SIEM rule(s) / protocol(s) and (b) providing an automated mechanism for generating and deploying a SIEM rule / protocol (Security Information & Event Management) to be used by security monitoring engines at customer (i.e. tenant) monitored computing environments hosted by various tenant servers to improve security monitoring capability).
As per claim 9, Cristofi as modified teaches aggregating, via the SIEM management application, the plurality of tenant servers into workspaces based, at least in part, on the common solution bundle (Cristofi: see above & Para [0258] / [0531] / [0647] and Para [1008]: formatted as JavaScript Object Notation, or JSON messages (i.e. a JSON based solution bundle), the data records being obtained from various data sources of IT assets (i.e. one type of log sources)) || (Milazzo: see above & Para [0002]: a SIEM system aggregating data from various data sources in order to identify deviations in the operation of the computing devices associated with these data sources from a normal operational state and then take appropriate responsive actions to the identified deviations).
As per claim 10, the instant claim is directed to a claimed content having functionality corresponding to the Claims 1, and are rejected by a similar rationale.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to LONGBIT CHAI whose telephone number is (571)272-3788. The examiner can normally be reached Monday - Friday 9:00am-5:00pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn D. Feild can be reached at 571-272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
---------------------------------------------------
/Longbit Chai/
Longbit Chai E.E. Ph.D.
Primary Examiner, Art Unit 2431
No. #2554 – 2026
---------------------------------------------------