DETAILED ACTION
This office action is in response to the application filed on 11/27/2024. Claim(s) 8-14 is/are pending and are examined.
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Priority/Benefit
Applicant’s priority claim is hereby acknowledged of 371 of PCT/JP2022/022305 06/01/2022, which papers have been placed of record in the file.
Information Disclosure Statement PTO-1449
The Information Disclosure Statement(s) submitted by applicant on 11/27/2024 and 11/20/2025 has/have been considered. The submission is in compliance with the provisions of 37 CFR § 1.97. Form PTO-1449 signed and attached hereto.
Examiner’s Note – Allowable Subject Matter
Claim 9 overcomes the prior art and would otherwise be allowable if incorporated into the base claim along with any intervening claims.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 8, 10-13 is/are rejected under 35 U.S.C. 103 as being unpatentable over Terada (US 2018/0332061 A1), in view of Joseph (US 2018/0084010 A1).
Regarding claims 8 and 10-11, Terada teaches:
“An attack detection and handling control system for performing detection and handling of a cyber attack (Terada, ¶ 29-30 teaches implementation with a processor, memory and medium to implement method steps), the attack detection and handling control system comprising: a controller configured to perform network control in an access network (Terada, Fig. 1 element 50 ¶ 26-27 teaches management server, i.e., controller, controlling network elements and policy); and a hardware accelerator configured to be connected to a communication device of the access network and to the controller (Terada, Fig. 1 elements 20 and 90 ¶ 26-27 teaches network monitoring apparatus, i.e., accelerator, connected to node, i.e., communication device), wherein the hardware accelerator comprises: a data acquisition unit configured to acquire communication data from the communication device (Terada, ¶ 26 and 31 monitoring apparatus acquires packets via communications acquisition unit 21); a data preprocessing unit configured to perform, on the acquired communication data, preprocessing of extracting predetermined data required for attack detection and performing statistical processing on the extracted predetermined data (Terada, ¶ 67-70 teaches preprocessing the acquired packets and classifying them),
an attack detection unit configured to receive a learning model for detecting an attack to be executed through the communication data from the controller and make a first determination in inline processing using the learning model as to whether the communication data acquired by the data acquisition unit is the attack (Terada, ¶ 47 teaches that the pattern data comes from the management server, i.e., controller. Terada, ¶ 67-70 teaches that the system is a learning model. Terada, ¶ 33-35 teaches detecting an attack. Terada, ¶ 47 teaches that the process is inline); a detection alert notification unit configured to generate a detection alert including detection information and network information, the detection information including a detection reason of the communication data determined as the attack, the network information being related to the communication data (Terada, ¶ 32, 72, 82, and 97-98 teaches issuing an alert of the attack with the pertinent information); and a handling performance unit configured to acquire, and perform, based on the acquired handling control policy, the attack handling on the communication data acquired by the data acquisition unit in inline processing (Terada, ¶ 32, 72, 82, and 97-98 teaches implementing a countermeasure to the attack)”.
Terada does not, but in related art, Joseph teaches machine to machine interactions as well as:
“wherein the controller comprises:
a learning unit configured to receive the preprocessed data from the hardware accelerator and, based on the received preprocessed data, generate the learning model for detecting the attack to be executed through the communication data (Joseph, ¶ 67, 76-78, 80, and 89 teaches communicating with the threat detection system 105 to analyze received information using a learning model); and a handling determination unit configured to receive the detection alert from the hardware accelerator, make a second determination using the received detection alert as to whether attack handling is required, and when the second determination is that attack handling is required, create the handling control policy so as to include a type of the attack and a handling technique and transmit the handling control policy to the hardware accelerator (Joseph, ¶ 67, 76-78, 80-90, and 105, teaches interacting with the threat detection system in real time, dynamically creating new policies in response to detecting anomalies and attacks at multiple levels and sending the information to the other systems)”.
Before applicant’s earliest effective filing it would have been obvious to one of ordinary skill in the art, having the teachings of Terada and Joseph, to modify the attack detection system of Joseph to include the machine learning dynamic policy generation system as taught in Joseph. The motivation to do so constitutes applying a known technique to known devices and/or methods ready for improvement to yield predictable results.
Regarding claim 12, Terada teaches:
“A hardware accelerator configured to be connected to a controller that performs network control in an access network and to a communication device of the access network Terada, Fig. 1 elements 20 and 90 ¶ 26-27 teaches network monitoring apparatus, i.e., accelerator, connected to node, i.e., communication device), the hardware accelerator comprising: a data acquisition unit configured to acquire communication data from the communication device (Terada, ¶ 26 and 31 monitoring apparatus acquires packets via communications acquisition unit 21); a data preprocessing unit configured to perform, on the acquired communication data, preprocessing of extracting predetermined data required for attack detection and performing statistical processing on the extracted predetermined data (Terada, ¶ 67-70 teaches preprocessing the acquired packets and classifying them), an attack detection unit configured to receive a learning model for detecting an attack to be executed through the communication data from the controller and make a first determination in inline processing using the learning model as to whether the communication data acquired by the data acquisition unit is the attack (Terada, ¶ 47 teaches that the pattern data comes from the management server, i.e., controller. Terada, ¶ 67-70 teaches that the system is a learning model. Terada, ¶ 33-35 teaches detecting an attack. Terada, ¶ 47 teaches that the process is inline); a detection alert notification unit configured to generate a detection alert including detection information and network information and transmits the detection alert to the controller, the detection information including a detection reason of the communication data determined as the attack, the network information being related to the communication data (Terada, ¶ 32, 72, 82, and 97-98 teaches issuing an alert of the attack with the pertinent information); and a handling performance unit configured to acquire, and perform, based on the acquired handling control policy, the attack handling on the communication data acquired by the data acquisition unit in inline processing (Terada, ¶ 32, 72, 82, and 97-98 teaches implementing a countermeasure to the attack)”.
Terada does not, but in related art, Joseph teaches:
“transmit the preprocessed data to the controller (Joseph, ¶ 67, 76-78, 80, and 89 teaches communicating with the threat detection system 105 to analyze received information using a learning model);
from the controller, a handling control policy including information required for attack handling (Joseph, ¶ 67, 76-78, 80-90, and 105, teaches interacting with the threat detection system in real time, dynamically creating new policies in response to detecting anomalies and attacks at multiple levels and sending the information to the other systems)”.
Before applicant’s earliest effective filing it would have been obvious to one of ordinary skill in the art, having the teachings of Terada and Joseph, to modify the attack detection system of Joseph to include the machine learning dynamic policy generation system as taught in Joseph. The motivation to do so constitutes applying a known technique to known devices and/or methods ready for improvement to yield predictable results.
Regarding claims 13 and 14, Terada teaches:
“A controller configured to be communicably connected with a hardware accelerator connected to a communication device of an access network (Terada, ¶ 29-30 teaches implementation with a processor, memory and medium to implement method steps. Terada, Fig. 1 element 50 ¶ 26-27 teaches management server, i.e., controller, controlling network elements and policy. Terada, Fig. 1 elements 20 and 90 ¶ 26-27 teaches network monitoring apparatus, i.e., accelerator, connected to node, i.e., communication device)”.
Terada does not, but in related art, Joseph teaches machine to machine interactions as well as:
“the controller comprising: a learning unit configured to acquire, from the hardware accelerator, communication data on which preprocessing of extracting predetermined data required for attack detection and performing statistical processing on the extracted predetermined data has been performed and generate a learning model for detecting an attack to be executed through the communication data (Joseph, ¶ 67, 76-78, 80, and 89 teaches communicating with the threat detection system 105 to analyze received information using a learning model); and a handling determination unit configured to acquire a detection alert on the communication data in which the attack is detected by the hardware accelerator using the learning model, make a determination using the acquired detection alert as to whether attack handling is required, and when the determination is that the attack handling is required, create a handling control policy including a type of the attack and a handling technique and transmit the handling control policy to the hardware accelerator (Joseph, ¶ 67, 76-78, 80-90, and 105, teaches interacting with the threat detection system in real time, dynamically creating new policies in response to detecting anomalies and attacks at multiple levels and sending the information to the other systems)”.
Before applicant’s earliest effective filing it would have been obvious to one of ordinary skill in the art, having the teachings of Terada and Joseph, to modify the attack detection system of Joseph to include the machine learning dynamic policy generation system as taught in Joseph. The motivation to do so constitutes applying a known technique to known devices and/or methods ready for improvement to yield predictable results.
Conclusion
In the case of amending the claimed invention, Applicant is respectfully requested to indicate the portion(s) of the specification which dictate(s) the structure relied on for proper interpretation and also to verify and ascertain the metes and bounds of the claimed invention.
The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure: See PTO-892.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Stephen T Gundry whose telephone number is (571) 270-0507. The examiner can normally be reached Monday-Friday 9AM-5PM (EST).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Amir Mehrmanesh can be reached at (571) 270-3351. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/STEPHEN T GUNDRY/Primary Examiner, Art Unit 2435