DETAILED ACTION
Claims 1-13, and 15-20 are presented for consideration.
Response to Arguments
2. Applicant's arguments filed 06/18/2026 have been fully considered but they are not persuasive.
As per remarks, Applicants argued that (1) in Rhodes, no instructions are sent to any of the observation points and the behavior of the observation points as well as the detail level of the network information summarized by the observation points are not modified or changed in anyway, Rhodes is completely silent regarding any communication from the data analysis system to the observation points that would instruct the observation points to change how they collect or generate data.
As to point (1), Rhodes discloses user interface may accept user commands for modifying any of the first, second, or third sets of configuration parameters, one or more of the configuration parameters may be modified after abnormal activity is initially detected, so that a subset of the network activity corresponding to the abnormal activity can be subsequently collected, generated and/or analyzed for much greater detail [ i.e. broadly interpreted as communication from the data analysis system to the observation points to change how they collect or generate data as argued ] [ paragraphs 0061 ]. In addition, Rhodes discloses one or more capture modules may be dynamically reconfigured for characterizing a subsequent flow record stream, a higher level capture module may be reconfigured for collecting additional data from a subsequent flow record stream, therefore, the collection of additional data is generally achieved by selecting a different set of configuration parameters for collection module(s) within one or more levels of captures modules [ i.e. broadly interpreted as instructing the one or more agent computing nodes to change the detail level of observation data that they collect as claimed ] [ Figure 1D; and paragraphs 0063-0066 ]. Also, Rhodes discloses “Drill Forward” refers to the process of obtaining additional information about a particular observation points (e.g. a particular network node, host server, or subscriber), the Drill Forward technique enables real-time investigation into abnormal network activity by allowing real-time modification of capture module configuration parameters [ i.e. broadly interpreted as instructing the one or more agent computing nodes to change the detail level of observation data that they collect as claimed ] [ paragraphs 0084-0089, and 0093 ]. As such, the claims, as written, are unpatentable over the cited prior art.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claim(s) 1-5, 7, 11-13, 15-18, and 20 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Rhodes [ US Patent Application No 2005/0234920 ].
As per claim 1, Rhodes discloses the invention as claimed including a method performed by a controller computing node to dynamically change a detail level of observation data collected by an observability system, the method comprising:
receiving observation data collected by a plurality of agent computing nodes [ i.e. collection modules for collect flow records from an observation point ] [ 132, Figure 1C; Abstract; and paragraphs 0045, 0047, 0070, and 0071 ];
determining, based on analyzing the observation data collected by the plurality of agent computing nodes, that a detail level of observation data collected by one or more of the plurality of agent computing nodes is to be changed [ i.e. drill forward refers to the process of obtaining additional information about a particular observation point; alter a magnification level by which a subset of the network activity is monitored ] [ Abstract; and paragraphs 0083-0087 ]; and
responsive to determining that the detail level of observation data collected by the one or more agent computing nodes is to be changed, instructing the one or more agent computing nodes to change the detail level of observation data that they collect [ i.e. collection of additional data is achieved by selecting a different set of configuration parameters for collection modules, and accept user commands for modifying any of the first, second or third sets of configuration parameters ] [ 350, Figure 3; and paragraphs 0048, 0061, 0065, and 0085 ].
As per claim 2, Rhodes discloses wherein the one or more agent computing nodes are those of the plurality of agent computing nodes that have been determined to be associated with an anomaly that was detected based on analyzing the observation data collected by the plurality of agent computing nodes [ i.e. if abnormal network activity is detected on a particular server port ] [ 340, Figure 3; and paragraphs 0034, 0035, and 0085 ].
As per claim 3, Rhodes discloses wherein the observation data collected by the plurality of computing nodes is analyzed using a rule-based algorithm or a machine leaning algorithm [ i.e. analysis model to be used for analyzing ] [ paragraphs 0050, and 0053-0057 ].
As per claim 4, Rhodes discloses wherein the observation data collected by the plurality of computing nodes includes measurement data and trace data [ i.e. network probes and traces ] [ paragraphs 0028, and 0088 ].
As per claim 5, Rhodes discloses wherein instructing the one or more agent computing nodes to change the detail level of observation data that they collect causes the one or more computing nodes to collect more detailed observation data than before [ i.e. obtaining additional information about the abnormal network activity that was not previously collected ] [ paragraphs 0035, and 0048 ].
10. As per claim 7, Rhodes discloses the invention as claimed including a method performed by an agent computing node to change a detail level of observation data collected by the agent computing node, the method comprising:
collecting first observation data in accordance with a first observation data collection setting that corresponds to a first detail level [ i.e. collection modules for collect flow records from an observation point ] [ 132, Figure 1C; Abstract; and paragraphs 0045, 0047, 0070, and 0071 ];
receiving, from a controller computing node, an instruction to change the detail level of observation data collected by the agent computing node [ i.e. drill forward refers to the process of obtaining additional information about a particular observation point; alter a magnification level by which a subset of the network activity is monitored ] [ Abstract; and paragraphs 0083-87 ];
responsive to receiving the instruction to change the detail level of observation data collected by the agent computing node, changing an observation data collection setting of the agent computing node from the first observation data collection setting to a second observation data collecting setting that corresponds to a second detail level that is different from the first detail level [ i.e. collection of additional data is achieved by selecting a different set of configuration parameters for collection modules, and accept user commands for modifying any of the first, second or third sets of configuration parameters ] [ 350, Figure 3; and paragraphs 0048, 0061, 0065, and 0085 ]; and
collecting second observation data in accordance with the second observation data collection setting [ i.e. one or more of the configuration parameters may be modified after abnormal activity is initially detected, so that a subset of the network activity corresponding to the abnormal activity can be subsequently collected ] [ paragraphs 0061, 0062, 0065, 0085, and 0088].
11. As per claim 11, Rhodes discloses determining, based on detecting a condition, that the detail level of observation data collected by the agent computing node is to be changed [ i.e. alter magnification level by which a subset of the network activity is monitored] [ Abstract; and paragraph 0062 ]; responsive to determining that the detail level of observation data collected by the agent computing node is to be changed, changing the observation data collection setting of the agent computing node from the second observation data collection setting to a third observation data collection setting that corresponds to a third detail level that is different from the second detail level; and collecting third observation data in accordance with the third observation data collection setting [ i.e. altered to focus on a particular subset of the flow record stream where the abnormal activity occurred [ paragraphs 0085-0087 ].
12. As per claim 12, Rhodes discloses wherein the condition includes one or more of: an existence of an anomaly in an operation of the agent computing node, a change in an operational status of the agent computing node, and a change in an amount of resources used by the agent computing node [ i.e. abnormal network activity such as caused by network congestion and network security breaches ] [ Abstract; and paragraphs 0021, 0030, and 0083 ].
13. As per claims 13, 15-18, they are rejected for similar reasons as stated above in claims 1-5.
14. As per claim 20, it is rejected for similar reasons as stated above in claim 1.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 6, 8-10 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Rhodes [ US Patent Application No 2005/0234920 ], in view of Holeman et al. [ US Patent Application No 2018/0191766 ].
As per claim 6, Rhodes does not specifically disclose sending, to an agent computing node from the plurality of agent computing nodes, a request for observation data collected by the agent computing node that is temporarily stored in a non-persistent storage of the agent computing node and was not sent by the agent computing node to the controller computing node. Holeman discloses sending, to an agent computing node from the plurality of agent computing nodes, a request for observation data collected by the agent computing node that is temporarily stored in a non-persistent storage of the agent computing node and was not sent by the agent computing node to the controller computing node [ i.e. local analysis logic and cache logic take the information collected by sensors, perform an optional local analysis, and determine the format, granularity, and size of the data, which may be sent to network and/or cached for later use ] [ 430, Figure 4; and paragraphs 0057, 0060 and 0063 ]. It would have been obvious to a person skill in the art before the effective filing date of the claimed invention to combine the teaching of Rhodes and Holeman because the teaching of Holeman would enable to perform assessment of system activity dynamically using an algorithm that considers multiple metrics [ Holeman, paragraph 0018 ].
17. As per claim 8, Holeman discloses sending, to the controller computing node, a first subset of the first observation data; and temporarily storing, in a non-persistent storage of the agent computing node, a second subset of the first observation data that was not included in the first subset of the first observation data [ i.e. cache logic retains data for a configuration holding period ] [ paragraphs 0063, 0085, and 0102 ].
18. As per claim 9, Holeman discloses receiving, from the controller computing node, a request for observation data included in the second subset of the first observation data; and responsive to receiving the request for the observation data included in the second subset of the first observation data, retrieving the requested observation data from the non-persistent storage and sending the requested observation data to the controller computing node [ i.e. cache logic may determine that additional data detail is needed to complete its analysis, and if a request for this additional data is made during the holding period, cache logic can supply this information ] [ paragraphs 0063, and 0078 ].
19. As per claim 10, Holeman discloses overwriting, in the non-persistent storage, the second subset of the first observation data with new observation data collected by the agent computing node after the first observation data was collected [ i.e. control local retention, how long the collected information is stored by a cache ] [ paragraphs 0085, and 0086 ].
20. As per claim 19, it is rejected for similar reasons as stated above in claim 6.
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to DUSTIN NGUYEN whose telephone number is (571)272-3971. The examiner can normally be reached Monday-Friday 9-6 PST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Brian Gillis can be reached at 571-2727952. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/DUSTIN NGUYEN/Primary Examiner, Art Unit 2446