Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Arguments
This communication is in response to filing of 06/24/2026. Claims 1-7, 11-20 are pending. Applicant’s arguments with respect to the prior art rejections (35 USC 103) of amended claim(s) have been fully considered but they are not persuasive.
Applicant’s Argument:
Regarding the limitation requiring generating "a set of suggested tasks, wherein each suggested task of the set of suggested tasks represents techniques for isolating a host connected to the computer network if the data has been compromised," the Examiner has alleged that Mills teaches this limitation at paragraphs [0032] and [0051]-[0053], which describe context-sensitive actions presented as selectable buttons adjacent to log entries. See Office Action, pages 6-7. However, Applicant respectfully submits that the actions disclosed in Mills are general-purpose IT administration tasks, not security isolation techniques. As described in Mills, the exemplary actions include "increasing a user's disk quota; rerouting network traffic away from an overheating server; purchasing additional server capacity from a cloud provider; purchasing physical hard disks from an Internet merchant such as Amazon.com; delaying a scheduled software update; causing a user to be logged out; causing a user to change his or her password on next login; activating a load balancer or other device; activating security measures in a secured data center; activating fire suppression measures in a secured data center; restarting a server or application." See Mills, paragraph [0027]. None of these actions constitute "techniques for isolating a host connected to the computer network if the data has been compromised," as recited by claim 1. Mills'context- sensitive actions are directed to routine administrative tasks such as increasing disk quotas and rebooting servers in response to operational events like running out of disk space or server overheating-not to security incident response involving host isolation following a data compromise.
Martin similarly does not cure this deficiency. The Examiner has not specifically mapped this limitation to Martin. To the extent Martin discloses "quarantining one or more compromised computers within the network" at paragraph [0024], this quarantining is an automatic system action executed upon confirmation of a threat, not a "set of suggested tasks" generated and presented for user-guided incident response. See Martin, paragraph [0024]. Martin does not generate a set of suggested tasks representing isolation techniques; rather, Martin automatically executes quarantine actions. Claim 1, by contrast, requires generating a set of suggested tasks where each suggested task represents a technique for isolating a host-a recommendation workflow for guiding a user through security incident response. Neither Mills nor Martin , individually or in combination, teaches or suggests this limitation.”
Examiner’s Response:
The examiner respectfully disagrees. Although Mills does demonstrate some examples of IT administration tasks, Mills-Martin also discloses security isolation techniques well known to one of ordinary skill in the art such as Mills [0027] “causing a user to be logged out; causing a user to change his or her password on next login” or otherwise “activating security measures in a secured data center". This is especially apparent when considering Mills’ disclosure that “A combination of log entries associated with a user and/or server/device may trigger certain actions (e.g., a predetermined number of occurrences of the same error condition/log entry for a particular user and/or server/device may trigger certain actions).”. For example, a well-known security isolation technique is causing a user to be logged out or change his or her password in relation to repeated log in errors. The combination of Mills-Martin provides further techniques for isolating a host connected to the computer network if the data has been compromised in that Martin [0014] discloses “the system can identify a cyber attack already extant on the network, trigger an investigation into the cyber attack, and/or automatically quarantine compromised assets rapidly”.
Applicant’s Arguments:
“Regarding the limitation requiring identifying "key events linked to same processes, users, files, or network connections of events highlighted by the malicious or the suspicious indicators," the Examiner has alleged that Martin teaches this limitation at paragraph [0023]. See Office Action, pages 8-9. However, Applicant respectfully submits that Martin does not teach this lateral correlation step. As recited by claim 1, once known events are identified based on malicious or suspicious indicators, the system identifies other events-key events-that share the same processes, users, files, or network connections as the events that were flagged. This is a lateral expansion: the system discovers events that were not themselves flagged as malicious but are linked via shared attributes (same user, same process, same file, or same network connection) to events that were flagged.
Martin, by contrast, performs direct IOC matching-comparing log data against externally- defined threat indicator values. As described in Martin, the system "automatically scans the compressed log file for common elements between the compressed log file and the new threat intelligence information in Block S130, such as for an element in the compressed log file that indicates that a computer on the network previously connected to IP address 88.6.14.33 or previously connected to mwindowsupdate5.com." See Martin, paragraph [0023]. Martin queries log data for predefined IOC values (IP addresses, URLs) supplied by external threat intelligence. Martin does not identify previously-unflagged events that share processes, users, files, or network connections with events that were flagged as malicious. The distinction is significant: claim 1 requires discovering events not themselves flagged as malicious but linked via shared attributes to events that were flagged, whereas Martin simply matches log entries against externally-supplied IOC values. This lateral expansion from flagged events to related-but-unflagged events is fundamentally different from the direct IOC value matching of Martin. Neither Mills nor Martin teaches or suggests this limitation.”
Examiner’s Response:
The examiner respectfully disagrees. Martin demonstrates identifying “key events linked to same processes, users, files, or network connections of events highlighted by the malicious or the suspicious indicators," in that the system "automatically scans the compressed log file for common elements between the compressed log file and the new threat intelligence information in Block S130, such as for an element in the compressed log file that indicates that a computer on the network previously connected to IP address 88.6.14.33 or previously connected to mwindowsupdate5.com." See Martin, paragraph [0023]. The previous connections, for example, provide for key events in that they are linked to network connections of events highlighted by suspicious indicators, or threat intelligence information. These log files are scanned such that previously unassociated information is further contextualized ([0023] “if the system finds one or more common elements between the compressed log file and the new threat intelligence in Block S130, the system can determine that an attack… is possible”). Claim 1, as currently amended, does not include limitations that specify identifying previously-unflagged events that share processes, users, files, or network connections with events that were flagged as malicious. However, discovering events not themselves flagged as malicious but linked via shared attributes to events that were flagged is provided by Martin’s disclosure of scanning log files to discover the common elements -network connections, for example, in order to determine an attack, as the events themselves may not constitute an attack alone.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) (1-4 & 7), (11-13), (16-19) is/are rejected under 35 U.S.C. 103 as being unpatentable over MILLS (US 20140082513 A1), hereafter MILLS, in view of MARTIN (US 20180004942 A1), hereafter MARTIN.
Regarding claim 1, MILLS teaches:
A computer security method for analyzing a plurality of data sets for remediating security incidents in a cloud-based response system (MILLS [0004] “In accordance with the disclosed subject matter, systems, methods, and non-transitory computer-readable media provide for context-sensitive interactive logging.”, [0027] A wide variety of actions can be associated with one or more log entries. For example, the actions can include… causing a user to be logged out; causing a user to change his or her password on next login…activating security measures in a secured data center [0042] “Firewall 107 may provide security features, access control, authentication, spam protection, port blocking/port mapping, address mapping, active intrusion detection, and/or other features for the enterprise network.”, [0076] “In some embodiments, log server 601 can reside in a data center and form a node in a cloud computing infrastructure… A log server 601 in the cloud can be managed using a management system.”), the computer security method comprises: retrieving logs of data from a computer network(MILLS [0062] “The administrative user can access the interactive log by requesting a global timeline (i.e., unfiltered but ordered by time), a user timeline (i.e., filtered to retrieve only log entries of a particular user)… If the administrative user accesses the interactive log, all log entries corresponding to the requested filters may be retrieved from the relevant database…”); parsing the logs of data (MILLS [0045] “In some embodiments, log server 104 may include a log file or database for providing basic logging functionality for an application. These log entries may then be parsed by log server”) and filtering the logs of data into the plurality of data sets(MILLS [0006] “the plurality of log entries can be filtered based on information in the at least one category of data selectable by the user at the administrative user console; and responsive to a selection of the at least one category of data from the administrative user console, filter the plurality of log entries for display.”, [0024] “The disclosed logging system also allows filtering based on the above data categories. When an administrative user chooses to view only log entries that match a specified filter, all entries that do not match the filter can be hidden. This allows for simple viewing of logs that pertain only to a specific user, for example, or a particular server or device.”), wherein the filtering of the logs of data includes: creating an event timeline of the computer network (MILLS [0062] “The administrative user can access the interactive log by requesting a global timeline (i.e., unfiltered but ordered by time), a user timeline (i.e., filtered to retrieve only log entries of a particular user), a device timeline (only for a particular device), or an application timeline (only for a particular application).”) ;and generating, based on a result of the identification of whether the data from the logs of data is accessed by the unauthorized computing system, a set of suggested tasks, wherein each suggested task of the set of suggested tasks represents techniques for isolating a host connected to the computer network if the data has been compromised (MILLS [0032] “After one or more log entries is associated with an action, the action may be presented together with the one or more log entries to the administrative user… the association is stored in a storage system, such as a database, and the stored association is used to provide the log entry and each of its associated actions when the administrative user chooses to retrieve the log entry at a later date. There may be one action, more than one action, or no actions associated with a given log entry… In some embodiments, a button may be shown next to one or more log entries;”, [0051] “In some embodiments, context-specific actions can be presented to the administrative user as selectable buttons located adjacent to the log entry that provides the relevant context.”, [0027] “A wide variety of actions can be associated with one or more log entries. For example…causing a user to be logged out; causing a user to change his or her password on next login… activating security measures in a secured data center". See further Mills’ disclosure that [0027] “A combination of log entries associated with a user and/or server/device may trigger certain actions (e.g., a predetermined number of occurrences of the same error condition/log entry for a particular user and/or server/device may trigger certain actions).” And [0042] “Firewall 107 may provide security features, access control, authentication, spam protection, port blocking/port mapping, address mapping, active intrusion detection, and/or other features for the enterprise network. For example, a well-known security isolation technique is causing a user to be logged out or change his or her password in relation to repeated log in errors.).
Further regarding claim 1, MILLS teaches the limitations previously demonstrated, however does not appear to explicitly teach the following limitations demonstrated by MARTIN:
creating an event timeline of the computer network by identifying: (a) known events based on malicious or suspicious indicators on the logs of data(MARTIN [0018] “The system can apply new threat intelligence to a network accounting log of the network to detect cyber attacks already present on a machine within the network. Threat intelligence for a particular security threat can define: an actor; tools, techniques, processes (TTPs) of the actor; and indicators of compromise (IOCs) for such an attack…IOCs for a particular cyber attack can also specify: unusual (outbound) network traffic; unusual privileged user account activity; log-in anomalies; increases in database read volume; suspicious registry or system file changes;”, [0022] “Upon receipt of this new threat intelligence information for Red Gang 13, the system adds this new threat intelligence information to an existing threat corpus of threat intelligence of known threats and automatically scans the network event buffer for elements that match IOCs defined in the threat corpus.”, [0054] “The system can additionally or alternatively implement pattern-matching techniques to calculate a degree of temporal alignment between singular network events in the network accounting log and threat elements defined in the new threat intelligence that may suggest presence of the newly-identified security threat on the network now or in the past. In one example, threat intelligence for a newly-identified security threat defines an attack pattern, including a relative timeline of one or more initial infiltration, command and control, reconnaissance, and lateral movement stages of a cyber attack.”), (b) key events linked to same processes, users, files, network connections of events highlighted by the malicious or the suspicious indicators(MARTIN [0023] “[0023] Separately and upon receipt of this new threat intelligence information for Red Gang 13, the system automatically scans the compressed log file for common elements between the compressed log file and the new threat intelligence information in Block S130, such as for an element in the compressed log file that indicates that a computer on the network previously connected to IP address 88.6.14.33 or previously connected to mwindowsupdate5.com.”), (c) incident events with a time period matching the known events and the key events (MARTIN [0023] “However, if the system finds one or more common elements between the compressed log file and the new threat intelligence in Block S130, the system can determine that an attack by Red Gang 13 on the credit union's internal network is possible…”), and primary events from the known events, key events, and incident events (MARTIN [0023] “…the system can then scan the network accounting log—containing original, uncompressed network event data—for a group or cluster of event records that may confirm such an attack by Red Gang 13 on the internal network in Block S140.”, [0068] “Similarly, the system can execute attack-type specific processes based on threat intelligence for a confirmed cyber attack type.” The confirmed attacks are mapped to primary events.); analyzing using a data analysis system (MARTIN [0017] “The system can interface with an Information Sharing and Analysis Center (“ISAC”) to access an ISAC database containing definitions for a current set of known security threats (or “threat intelligence”)… In particular, as newly-identified security threats and cyber attacks are identified by members of the ISAC or by external entities on behalf of the ISAC, the ISAC can add new threat intelligence pertaining to these newly-identified security threats and cyber attacks to the ISAC database. The ISAC database can then distribute updated threat intelligence to related entities, including the system. Alternatively, the system can regularly pull threat intelligence updates from the ISAC database, such as once per day.”), the event timeline of the computer network from the plurality of data sets to identify whether data from the logs of data is accessed by an unauthorized computing system (MARTIN [0023] “the system can then scan the network accounting log—containing original, uncompressed network event data—for a group or cluster of event records that may confirm such an attack by Red Gang 13 on the internal network in Block S140. In particular, the system can implement pattern matching techniques in Block Size S140 to identify various elements in the network accounting log that match IOC values contained in the new threat intelligence, such as a combination of common external IP address, MAC address, hostname, URL, and event sequence or timeline between the network accounting log and the new threat intelligence.”, [0026] “In particular, new events occurring at computers within the network may be scanned for possible security threats in real-time or in near real-time by other detection mechanisms—such as external intrusion detection systems (IDS) or intrusion prevention systems (IPS)”), wherein the primary events are associated with the unauthorized computing system (MARTIN [0023] “the system can then scan the network accounting log—containing original, uncompressed network event data—for a group or cluster of event records that may confirm such an attack by Red Gang 13 on the internal network in Block S140.”);
Since MILLS and MARTIN are from the same field of endeavor as both are directed to secure memory log functions, which is within the same field of endeavor as the claimed invention, it would have been obvious to one of ordinary skilled in the art before the effective filing date of the claimed invention to modify and combine the teachings of MILLS and MARTIN by incorporating the teachings of MARTIN into MILLS. The motivation to combine is to improve network security logging functions and verification thereof. (MILLS [AB]; MARTIN [AB]).
Regarding claim 2, MILLS-MARTIN teaches:
The computer security method for analyzing a plurality of data sets for remediating security incidents in a cloud-based response system as recited in claim 1, further comprises presenting the set of suggested tasks on a user interface ([0005] “configured to…identify at least one action associated with the logging event… format an interactive display page, for display at the administrative user console, containing the log entry, wherein the interactive display page displays the logging event and the associated action in proximity to the logging event, and wherein the associated action can be selectable by an administrative user at the administrative user console, and responsive to a selection of the associated action from the administrative user console, initiate the associated action.”, [0053] “For example, log entry 214, "User sent request for login to email server," has no appropriate action next to it. In other cases, an action may be associated with more than one log entry. The action may be displayed next to each of the log entries or alternatively may be displayed next to only one log entry.”, ).
Regarding claim 3, MILLS-MARTIN teaches:
The computer security method for analyzing a plurality of data sets for remediating security incidents in a cloud-based response system as recited in claim 1, wherein identifying if the network has been accessed by the unauthorized computing system includes the computing system modifying, deleting and/or acquiring data to the network without authorization(MILLS [0042] “Firewall 107 may provide security features, access control, authentication, spam protection, port blocking/port mapping, address mapping, active intrusion detection, and/or other features for the enterprise network.”, MARTIN [0015] “The system can additionally or alternatively interface with external intrusion detection systems and/or intrusion prevention systems that both detect network events and compare these network events to known threat intelligence to detect such known threats on the network substantially in real-time.)”, [0018] “The system can apply new threat intelligence to a network accounting log of the network to detect cyber attacks already present on a machine within the network… For example, threat intelligence for a particular cyber attack performed by an actor can include TTPs that specify one or more of: attack patterns; malware; exploits; kill chains; tools; infrastructure; victim targeting; malicious code; tunneling; viruses or worms; keyloggers; spyware; malicious rootkits; etc.”).
Regarding claim 4, MILLS-MARTIN teaches:
The computer security method for analyzing a plurality of data sets for remediating security incidents in a cloud-based response system as recited in claim 1, further comprises suggesting a set of tasks to a user, wherein the set of tasks includes executing a wizard, evaluating an enrichment to one or more log events, or managing a task using an auto- suggest technique(MILLS [0030] “In some embodiments, the log server may automatically learn which log entries should be associated with which actions by automatically recording administrative actions taken by the administrative user.” MARTIN [0024] “Upon confirmation of sufficient match between various elements in the network accounting log and in the new threat intelligence, the system can execute one or more actions to handle the threat on the internal network in Block S150, such as by automatically: issuing an alert that can be combined with other alerts to trigger human involvement; prompting human security personnel at an external security operation center (or “SOC”) to begin an investigation into the threat; and/or quarantining one or more compromised computers within the network.”).
Regarding claim 7, MILLS-MARTIN teaches:
The computer security method for analyzing a plurality of data sets for remediating security incidents in a cloud-based response system as recited in claim 1, further comprises identifying risks associated with the computer system, wherein the set of suggested tasks include predefined tasks including installing an anti-virus, disconnecting the unauthorized computing system and/or other remediations in response to the risks(MARTIN [0042] “A firewall 107 may be present in some embodiments, where a firewall is a network device that separates network 106 from the public Internet. Firewall 107 may provide security features, access control, authentication, spam protection, port blocking/port mapping, address mapping, active intrusion detection, and/or other features for the enterprise network.”, MILLS [0016] “Blocks of the method S100 can be executed by a remote computer system (e.g., a remote server) that remotely collects and stores network traffic data occurring on a network and compares these data to new threat intelligence … in order to asynchronously identify possible security threats and to prompt security personnel (e.g., a security analyst) to selectively investigate such possible security threats.”, [0024] “Upon confirmation of sufficient match between various elements in the network accounting log and in the new threat intelligence, the system can execute one or more actions to handle the threat on the internal network in Block S150, such as by automatically… quarantining one or more compromised computers within the network.”).
Regarding claims (11-13) and (16-19), claims 11-13 and 16-19 recite substantially similar limitations as claims (1-2 & 7) and (1-4) respectively, in the embodiment of “A non-transitory computer-readable medium comprising instructions that are executable by a processing device for causing the processing device to perform operations” and “A cloud-based response system for analyzing data for remediating security incidents in a cloud environment,” such as taught by MILLS-MARTIN(MILLS [0009] “In another embodiment, a non-transitory computer-readable medium is provided, the medium having executable instructions operable to, when executed by a computing device, cause the computing device to”, [0020] “Systems, methods, and non-transitory computer-readable media are provided for a context-sensitive, interactive log system.”, [0079] “The processes and logic flows described in this specification, including the method steps of the subject matter described herein, can be performed by one or more programmable processors executing one or more computer programs to perform functions of the subject matter described herein by operating on input data and generating output.”).
Claims (5-6), (14-15), and (20) are rejected under 35 U.S.C. 103 as being unpatentable over MILLS-MARTIN in further view of BERGER (US 11757907 B1), hereafter BERGER.
Regarding claim 5, MILLS-MARTIN teaches the limitations previously demonstrated, however does not appear to explicitly teach the following limitations demonstrated by BERGER:
The computer security method for analyzing a plurality of data sets for remediating security incidents in a cloud-based response system as recited in claim 1, wherein the primary events are presented with a signal that can indicate a vulnerability associated with a computing system of the computer network(BERGER column 5 lines 48-59 “Illustratively, the vulnerability user interface may be an interactive display that summarizes the vulnerabilities detected across the network, provides detailed information regarding individual vulnerabilities, and allows presentation at various degrees of granularity between these extremes. For example, the vulnerability user interface may include color-coded severity indicators and display objects that represent groups of vulnerabilities (e.g., groups of devices that each exhibit a particular vulnerability or set of vulnerabilities). A user may activate an individual display object to obtain more information about the group of devices/vulnerabilities that the display object represents.”), a prediction associated with the vulnerability (BERGER column 40 lines 39-49 “At block 1925, the cybersecurity AI/ML service 1742 may generate output data from the threat prediction model 1808A using the input data. Illustratively, the output data may include probabilities of particular threats being experienced by the target network based on the input data provided to the model 1808A. For example, the threat prediction model 1808A may produce probabilities for each possible threat that the model has been trained to analyze, probabilities for the n highest-probability threats that the model 1808A has produced for the target network, the highest-probably threat, or the like.), and a remediation for the vulnerability (BERGER column 40 lines 50-57 “At block 1930, the cybersecurity AI/ML service 1742 may provide information regarding the determined threats. The information may identify the highest-probability threat(s), the probabilities, recommended remediations, some combination thereof, etc. Illustratively, the information regarding the determined threats may be presented in any of a variety of modalities, such as: text-based and/or graphic-based presentations via a GUI;”).
Since MILLS-MARTIN and BERGER are from the same field of endeavor as both are directed to secure memory log functions, which is within the same field of endeavor as the claimed invention, it would have been obvious to one of ordinary skilled in the art before the effective filing date of the claimed invention to modify and combine the teachings of MILLS-MARTIN and BERGER by incorporating the teachings of BERGER into MILLS-MARTIN. The motivation to combine is to improve network security logging functions and verification thereof. (MILLS [AB]; MARTIN [AB]).
Regarding claim 6, MILLS-MARTIN in further view of BERGER teaches:
The computer security method for analyzing a plurality of data sets for remediating security incidents in a cloud-based response system as recited in claim 5, wherein the signal is generated using natural language processing (BERGER column 49 lines 30-36 “In some embodiments, other methods of input, output, and interactivity may be used. Illustratively, the cybersecurity assessment system 120 may provide automatic natural language dialogs instead of—or in addition to—any of the graphical user interfaces and other user-facing input/output methods described herein.”, column 49 lines 44-54 “The automated natural language dialogs may leverage data regarding assessments, solutions, threats, remediations, recommendations, and the like to guide users. For example, automated natural language dialogs may be used instead of—or in addition to—other user interfaces for performing audits of cybersecurity framework compliance, obtaining results of automated threat analysis generated using machine learning models, obtaining remediation recommendations generated using machine learning models, provisioning and maintaining the ongoing operation of cybersecurity services, and the like.).
Regarding claims (14-15) and (20), claims (14-15) and (20) recite substantially similar limitations as claims (5-6) and (5) respectively, in the embodiments of “A non-transitory computer-readable medium comprising instructions that are executable by a processing device for causing the processing device to perform operations” and “A cloud-based response system for analyzing data for remediating security incidents in a cloud environment,” such as taught by MILLS-MARTIN in view of BERGER (MILLS [0009] “In another embodiment, a non-transitory computer-readable medium is provided, the medium having executable instructions operable to, when executed by a computing device, cause the computing device to”, [0020] “Systems, methods, and non-transitory computer-readable media are provided for a context-sensitive, interactive log system.”, [0079] “The processes and logic flows described in this specification, including the method steps of the subject matter described herein, can be performed by one or more programmable processors executing one or more computer programs to perform functions of the subject matter described herein by operating on input data and generating output.”).
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
/K.J.G./Examiner, Art Unit 2408
/LINGLAN EDWARDS/Supervisory Patent Examiner, Art Unit 2408