Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-5, 7-15 and 17-20 are rejected under 35 U.S.C. 103 as being unpatentable over Hadden (US 2016/0072836) in view of Sharifi Mehr (US 10,521,584)
As per claim 1, Hadden discloses a method, comprising:
receiving data from edge nodes of a private network of a first entity at an external service (; ([0032]; The network cloud 26 can be a private network; [0035] The members of the IRT 172 can also communicate with the IM 102 using web browsers 150 or stand-alone applications running on user devices such as tablet devices, where the application server 140 additionally functions as a web server. ; [0053]; In step 406, a data security incident is detected, e.g., a data networking device such as a router 34 or firewall 36 in ACME Company's corporate network 70 detects data associated with a significant increase in download activity for a specific file, and sends data associated with the incident in messages to the ACME IM 102-1. Fig. 4: item 406)
of a security operations platform separate from the first entity ([0035] The members of the IRT 172 can also communicate with the IM 102 using web browsers 150 or stand-alone applications running on user devices such as tablet devices, where the application server 140 additionally functions as a web server.; [0053] In step 406, a data security incident is detected, e.g., a data networking device such as a router 34 or firewall 36 in ACME Company's corporate network 70 detects data associated with a significant increase in download activity for a specific file, and sends data associated with the incident in messages to the ACME IM 102-1.)
wherein the edge nodes of the private network comprise physical devices of the private network and ([0032] The enterprise network 131 of each organization includes a number of devices. These include computing devices, database systems, and data networking devices such as routers 34 firewalls 36 and configuration servers 63, in examples. The enterprise network 131 typically connects to the network cloud 26 via a firewall 36 device.)
of the private network and [0033] In the example enterprise network 131 for ACME Company, the firewall 36 also typically connects to a corporate network 70 of the enterprise network 131. A router 34 connects the corporate network 70 to a local network 72. The local network 72 also includes devices such as a user account database 58 including user accounts 60, and access server 160 including a web browser 150, and a security information and event manager (SIEM) 3)
detecting a security event in the private network from analyzing the received data at the external service; and (([0056] In step 412, the ACME IM 102 detects creation of the incident object 121 and optionally creation of IAs 120 associated with the incident, and parses their contents to identify any included data resources (e.g. IP addresses and the md5 hash for the downloaded file) within the incident object 121, and creates IAs 120 for the data resources identified within the incident object 121… Then, in step 414, the ACME IM 102-1 issues queries to first level TIS(s) 20 configured in the TIS configuration repository 128, to determine whether the IAs 120 (e.g. md5 hash for downloaded file and/or IP addresses of downloaded packets) for the incident object 121 are identified as known threats. Fig. 4: items 412, 414)
generating an output from the external service in response to detecting the security event that at least in part facilitates remediating the security event at one or more of the edge nodes of the private network; ([0061]; According to step 430, using the config API 39 of the configuration server 63, the IM 102 instructs reconfiguration of network devices within the client's enterprise network 131, e.g., send a message over the network cloud 26 to the configuration server 63 via the firewall 36, where the message includes instructions to block the bad IP addresses on the router 34 of the enterprise network 131; The config API 39 receives the message and forwards the message to the router 34 for execution on the router 34 in step 432. Fig. 5; items 430, 432)
Hadden fails to disclose virtual service provide to the private network by a third-party provider separate from the first entity and the security operations platform.
Sharifi Mehr discloses virtual service provide to the private network by a third-party provider separate from the first entity and the security operations platform. (Col 6 lines 8-42; FIG. 2, the threat analysis service generates a decoy virtual server 214 and deploys the decoy virtual server 214 into the customer environment by configuring a virtual network interface in the decoy virtual server 214 and configuring the customer virtual network 202 to communicate with the virtual network interface. The decoy virtual server 214 is configured to attract an attacker and cause the attacker to access a set of decoy data 216 stored in the decoy virtual server 214. For example, the decoy virtual server 214 may be assigned a name and identifier that resembles names and identifiers configured by the customer in the customer virtual network 202. In another example, the decoy virtual server 214 is configured with a resource configuration that matches those of the customer virtual server 204. )
It would have been obvious before the earliest effective filing date for the teachings of Hadden to be modified so that the external threat information source implement a virtual decoy server hosted by third party providers external to the first entity and the security operations platform. This would have been advantageous to detect and stop attacks on the networks and to mitigate and prevent severe compromise. (Sharifi Mehr, Col 1 lines 5-18) and simulate the attacks before it propagates to the networks.
As per claim 2, Hadden / Sharifi Mehr disclose the method of claim 1. Hadden discloses wherein the data comprises a data stream or sampled data. ([0053] In step 406, a data security incident is detected, e.g., a data networking device such as a router 34 or firewall 36 in ACME Company's corporate network 70 detects data associated with a significant increase in download activity for a specific file (data stream), and sends data associated with the incident in messages to the ACME IM 102-1)
As per claim 3, Hadden / Sharifi Mehr discloses the method of claim 1. Sharifi Mehr discloses wherein the security even is remediated at a virtual node of the private network corresponding to the virtual service. (n yet another example, the tracking data 224 may include credentials, codes, or other access information that allows the attacker to access a decoy service monitored by the threat analysis service. If the tracking data 224 is used to access the decoy service, the threat analysis service generates diagnostic information that indicates where the tracking data 224 originated from and may identify where the decoy service was accessed from.)
As per claim 4, Hadden / Sharifi Mehr disclose the method of claim 1. Hadden discloses wherein the data comprises flow data or log data. ([0053];ACME Company's corporate network 70 detects data associated with a significant increase in download activity for a specific file, and sends data associated with the incident in messages to the ACME IM 102-1.)
As per claim 5, Hadden / Sharifi Mehr disclose the method of claim 7. Hadden discloses wherein the security even is remediated at a physical device of the private network. ([0062] In step 434, using the config API 39 of the configuration server 63, the IM 102 instructs reconfiguration of user accounts 60 within the client's enterprise network 131, e.g., send a message over the network cloud 26 to the user account database 58, where the message includes instructions to disable the user account 60 of the user that downloaded the malicious file. The config API 39 receives the message and forwards the message to the user account database 58 for execution on the user account database 58 in step 436, in another aspect of this example.)
As per claim 7, Hadden / Sharifi Mehr disclose the method of claim 1. Hadden discloses wherein the external service provides security operations for the private network. ([0061]; According to step 430, using the config API 39 of the configuration server 63, the IM 102 instructs reconfiguration of network devices within the client's enterprise network 131, e.g., send a message over the network cloud 26 to the configuration server 63 via the firewall 36, where the message includes instructions to block the bad IP addresses on the router 34 of the enterprise network 131; The config API 39 receives the message and forwards the message to the router 34 for execution on the router 34 in step 432. Fig. 5; items 430, 432)
Sharifi Mehr discloses and the security even is detected based on at least data from the third-party provider that provides the virtual service. (Col 6 lines 8-42; FIG. 2, the threat analysis service generates a decoy virtual server 214 and deploys the decoy virtual server 214 into the customer environment by configuring a virtual network interface in the decoy virtual server 214 and configuring the customer virtual network 202 to communicate with the virtual network interface. The decoy virtual server 214 is configured to attract an attacker and cause the attacker to access a set of decoy data 216 stored in the decoy virtual server 214. For example, the decoy virtual server 214 may be assigned a name and identifier that resembles names and identifiers configured by the customer in the customer virtual network 202. In another example, the decoy virtual server 214 is configured with a resource configuration that matches those of the customer virtual server 204. )
As per claim 8, Hadden / Sharifi Mehr disclose the method of claim 1. Hadden discloses wherein the external service facilitates defending the private network from threats and attacks. ([0055], [0061]-[0062]; Fig. 4: items 414, 416; Fig. 5: items 428, 430, 432, 434)
As per claim 9, Hadden / Sharifi Mehr disclose the method of claim 1. Hadden discloses wherein the external service comprises a distributed intrusion detection and prevention system. ([0061]; According to step 430, using the config API 39 of the configuration server 63, the IM 102 instructs reconfiguration of network devices within the client's enterprise network 131, e.g., send a message over the network cloud 26 to the configuration server 63 via the firewall 36, where the message includes instructions to block the bad IP addresses on the router 34 of the enterprise network 131; The config API 39 receives the message and forwards the message to the router 34 for execution on the router 34 in step 432. Fig. 5; items 430, 432)
As per claim 10, Hadden / Sharifi Mehr disclose the method of claim 1. Hadden discloses wherein the output is generated by a rules engine of the external service that is configured to map the detected security event to an action. ([0042] The rules engine 178 generates a list of tasks 192 for an IM 102 or IRT personnel 172 to execute in response to data security incidents. The tasks 192 include recommended actions that should be taken to provide an incident response to the data security incidents.)
As per claim 11, Hadden / Sharifi Mehr disclose the method of claim 1. Hadden discloses wherein the output facilitates modifying routing at one or more of the edge nodes of the private network. ([0061]; According to step 430, using the config API 39 of the configuration server 63, the IM 102 instructs reconfiguration of network devices within the client's enterprise network 131, e.g., send a message over the network cloud 26 to the configuration server 63 via the firewall 36, where the message includes instructions to block the bad IP addresses on the router 34 of the enterprise network 131. The config API 39 receives the message and forwards the message to the router 34 for execution on the router 34 in step 432, in one example.)
As per claim 12, Hadden / Sharifi Mehr disclose the method of claim 1. Hadden discloses wherein the output facilitates modifying a corresponding security policy at one or more of the edge nodes of the private network ([0061]; According to step 430, using the config API 39 of the configuration server 63, the IM 102 instructs reconfiguration of network devices within the client's enterprise network 131, e.g., send a message over the network cloud 26 to the configuration server 63 via the firewall 36, where the message includes instructions to block the bad IP addresses on the router 34 of the enterprise network 131. The config API 39 receives the message and forwards the message to the router 34 for execution on the router 34 in step 432, in one example.)
As per claim 13, Hadden / Sharifi Mehr disclose the method of claim 1. Hadden discloses wherein the output comprises a routing filter or block list. ([0061]; According to step 430, using the config API 39 of the configuration server 63, the IM 102 instructs reconfiguration of network devices within the client's enterprise network 131, e.g., send a message over the network cloud 26 to the configuration server 63 via the firewall 36, where the message includes instructions to block the bad IP addresses on the router 34 of the enterprise network 131. The config API 39 receives the message and forwards the message to the router 34 for execution on the router 34 in step 432, in one example.)
As per claim 14, Hadden / Sharifi Mehr disclose the method of claim 1. Hadden discloses wherein the external service facilitates blocking threats or attacks post detection. ([0061]; According to step 430, using the config API 39 of the configuration server 63, the IM 102 instructs reconfiguration of network devices within the client's enterprise network 131, e.g., send a message over the network cloud 26 to the configuration server 63 via the firewall 36, where the message includes instructions to block the bad IP addresses on the router 34 of the enterprise network 131. The config API 39 receives the message and forwards the message to the router 34 for execution on the router 34 in step 432, in one example.)
As per claim 15, Hadden / Sharifi Mehr disclose the method of claim 1. Hadden discloses further comprising storing the received data at the external service. ([0045]; The IM 102 parses the incident object 121, identifies IP address 1.1.1.1 as a data resource, and creates an IA 120 for the identified IP address data resource (e.g. 1.1.1.1) and saves the IA 120 to the incident database 122.)
As per claim 17, Hadden / Sharifi Mehr discloses the method of claim 1.
Hadden discloses further comprising tagging the received data with metadata at the external service.( [0064] Returning to FIG. 4, in step 440, the ACME IM 102 queries the second level TIS(s) 30 configured in the TIS configuration repository 128, to obtain metadata and usage data for the identified IAs 120 within the incident object 121, and augments the IAs 120 with the obtained query results.)
Sharifi Mehr discloses wherein the virtual service comprises a virtual private cloud service. (Col 14 lines 4-26; ) At block 806, the threat analysis service generates a decoy virtual machine and connects the decoy virtual machine to the customer's network. The customer's network may be a subnet allocated to the customer, a virtual network allocated to the customer, or a protected internal network used by the customer. In some implementations, the threat analysis service generates a virtual private network (“VPN”) connection to an internal network used by the customer and connects th4e decoy virtual machine to the internal network via the VPN connection)
As per claim 18, Hadden / Sharifi Mehr disclose the method of claim 1. Hadden discloses further comprising providing a portal to the external service that is accessible to an operator of the private network.( [0034] Personnel typically associated with an Incident Response Team (“IRT”) 172 access the IM 102 via the browser 150. The browser 150, in one example, presents a graphical user interface (GUI) application for managing and interacting with the IM 102.)
As per claims 19-20, please see the discussion under claim 1 as similar logic applies.
Claim 6 is rejected under 35 U.S.C. 103 as being unpatentable over Hadden (US 2016/0072836) / Sharifi Mehr (US 10,521,584) / in view of Tagore (US 9,246,828)
As per claim 6, Hadden / Sharifi Mehr disclose the method of claim 1. The combined teachings of Hadden / Sharifi Mehr fail to disclose wherein data from different edge nodes comprises different sampling rates.
Tagore discloses wherein data from different edge nodes comprises different sampling rates. (( Col 2 lines 5-17; the method further comprises processing, with a flow controller within the service card of the network device, the subset of the inbound packets to generate flow records. In response to a change in the current packet rate at which the inbound packets are received at the interface, the flow controller adjusts the current sampling rate at which the forwarding circuit samples the inbound packets received at the interface. Col 2 lines 37-46; system 10 having a number of network elements (“E” in FIG. 1) 14A-14E, hereafter network elements 14. As shown in FIG. 1, each network element 14 generates traffic flow records and transmits the traffic flow records to flow collector 16. Network elements 14 may comprise dedicated computers, specialized devices, or virtual machines providing network services, such as network routers, gateways, switches, firewalls, hubs, servers, VPN appliances or other network devices that forward or otherwise provide services to traffic flows.; Col 2 lines 47-58; Network 6 may represent any type of packet-switched network, such as a service provider network, a customer network, an access network, a local area network (LAN))
It would have been obvious before the effective filing date of the invention for the combined teachings of Hadden / Sharifi Mehr to be modified so that the ACME IM adjust the sampling rates by configuring the edge nodes by adjusting the sampling rate of the edge nodes, such as routers, gateways firewalls, and switches, in the private company ACME Company's corporate. This would have been beneficial to improve the efficiencies and reduce the resources usages of the nodes in the private network.
Claim 16 is rejected under 35 U.S.C. 103 as being unpatentable over Hadden (US 2016/0072836) / Sharifi Mehr (US 10,521,584) further in view of Hasan (US 2017/0214701)
As per claim 16, Hadden / Sharifi Mehr disclose the method of claim 1. The combined teachings of Hadden / Sharifi Mehr fail to disclose further comprising indexing the received data for searchability at the external service.
Hasan discloses comprising indexing the received data for searchability at the external service. ([0006]; (e) Security Behavior, which stores and indexes events and their security responses and traits, wherein the response comprises block/approval decisions; [0233]; Events and their security responses and traits are stored and indexed for future queries.)
It would have been obvious before the earliest effective date for the teachings of Hadden / Sharifi Mehr to be modified so that the security data is indexed for searchability. This would have enabled administrator to refine security policies to the private network.
Claim 17 is rejected under 35 U.S.C. 103 as being unpatentable over Hadden (US 2016/0072836) / Sharifi Mehr (US 10,521,584) further in view of Matthews (US 11,003,723)
As per claim 17, Hadden / Sharifi Mehr disclose the method of claim 1. The combined teachings of Hadden/ Sharifi Mehr fail to disclose wherein the virtual service comprises a vitual private cloud service. ((Col 4 lines 23-34; Furthermore, the system (10) includes a cloud virtual private network (VPN) module operatively coupled to the local virtual private network (VPN) module (40). In one embodiment, the cloud VPN module (70) may be associated to a VPN network which may be created on a cloud platform. )
It would have been obvious before the earliest effective filing date of the invention for the combined teachings of Hadden / Sharifi Mehr the external threat information to be on a cloud VPN network. This would have beneficial because it allows for better security by stopping the breaches when accessing the deep web. (Matthews, Col 1 lines 20-28)
Response to Arguments
Applicant's arguments filed May 20, 2026 have been fully considered but they are not persuasive.
The terminal disclaimer filed on May 20, 2026 overcomes the obvious double patent rejections with respect to U.S. Patent No. 11,711,398.
Applicants argue, “Specifically, Thus, Applicant respectfully asserts that Hadden fails to disclose, teach, or suggest at least claim 1 as amended to recite at least "receiving data from edge nodes of a private network of a first entity at an external service of a security operations platform separate from the first entity, wherein the edge nodes of the private network comprise physical devices of the private network and a virtual service provided to the private network by a third-party provider separate from the first entity and the security operations platform;" As recited, this includes three distinct and separate elements (the first entity, the security operations platform, and the third-party provider). In contrast, the cited art appears to disclose only two elements (the application server, and the company. For example, the Office Action at page 10 cites to a incident managers for different companies and to an enterprise network. See e.g., Hadden ' [0031] ("IM(s) 102-1, 102-2, and 102-3 manage the incident response for enterprise networks 131 of exemplary organizations ACME Company, BigCorp, and CamCorp, respectively. ") However, such a citation fails to disclose, teach, or suggest at least the first entity at an external service of a security operations platform separate from the first entity and a virtual service provided to the private network by a third-party provider separate from the first entity and the security operations platform;". Thus, Applicant respectfully asserts that Hadden fails to disclose, teach, or suggest at least "receiving data from edge nodes of a private network of a first entity at an external service of a security operations platform separate from the first entity, wherein the edge nodes of the private network comprise physical devices of the private network and a virtual service provided to the private network by a third-party provider separate from the first entity and the security operations platform;".
Examiner points out the router is equated as the edge of of a private network of the first entity which is the user who downloaded the suspicious file on as the user of the private network or the client enterprise network is the first entity. Examiner argues that a router and a user who accesses the file are separate entities as the router sit at the edge of the edge node. As shown in Fig. 1, the ACME manager is separate from the router which is on the local network, and the router is separate from the first entity who downloaded the suspicious files. The user accessing the files and the routers are separate entities. The router forwards the security incident to the incident manager. Hadden shows that the network is separate on the router, user and the incident manager on the application server per [0032] and [0053]; and the router forwards the security incident to the ACME IM 102, which is the cloud network.
[0032] The enterprise network 131 of each organization includes a number of devices. These include computing devices, database systems, and data networking devices such as routers 34 firewalls 36 and configuration servers 63, in examples. The enterprise network 131 typically connects to the network cloud 26 via a firewall 36 device. The firewall 36 typically provides a single point of connection for each organization's enterprise network 131 to the network cloud 26. The network cloud 26 can be a private network, or a public network such as the Internet, in examples.
[0053] In step 406, a data security incident is detected, e.g., a data networking device such as a router 34 or firewall 36 in ACME Company's corporate network 70 detects data associated with a significant increase in download activity for a specific file, and sends data associated with the incident in messages to the ACME IM 102-1.
The ACME IM-2 at the application server functions as a security operations platform in that as Hadden discloses it reconfigures the user’s account upon detection of download of malicious code by the user per [0062] which is private to the first entity, the user as it resides on different networks.
[0062] In step 434, using the config API 39 of the configuration server 63, the IM 102 instructs reconfiguration of user accounts 60 within the client's enterprise network 131, e.g., send a message over the network cloud 26 to the user account database 58, where the message includes instructions to disable the user account 60 of the user that downloaded the malicious file. The config API 39 receives the message and forwards the message to the user account database 58 for execution on the user account database 58 in step 436, in another aspect of this example.
With respect to the discussion of virtual service, please refer to the body of the rejections.
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from theexaminer should be directed to Chirag R Patel whose telephone number is (571)272-7966. The examiner can normally be reached on Monday to Friday from 9:00AM to 6:00PM. If attempts to reach the examiner by telephone are unsuccessful, theexaminer's supervisor, Glenton Burgess, can be reached on 571-272-3949. The fax phone number for the organization where this application or proceedingis assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status informationfor published applications may be obtained from either Private PAIR or PublicPAIR. Status information for unpublished applications is available throughPrivate PAIR only. For more information about the PAIR system, seehttp://pairdirect.uspto.gov. Should you have questions on access to the PrivatePAIR system, contact the Electronic Business Center (EBC) at 866-217-9197(toll free).
/Chirag R Patel/
Primary Examiner, Art Unit 2454