DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Information Disclosure Statement
The information disclosure statements (IDS) submitted on 12/17/2024 and 10/16/2025 are in compliance with the provisions of 37 CFR 1.97. Accordingly, the information disclosure statement is being considered by the examiner.
Response to Amendment
Acknowledgment is made that claims 1-17 are canceled. Claims 18-33 are new and pending in the instant application.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
The following is a quotation of 35 U.S.C. 112 (pre-AIA ), second paragraph:
The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the applicant regards as his invention.
Claim 18 recites the limitation “receiving at least a threshold amount of encapsulated security packets (ESPs)”, the limitation defines the acronym for “encapsulated security packet(s)”. On line 6 the claim recites “ESP packet,” according to the definition this limitation could be read as “encapsulated security packet packet”, clarification and correction are requested.
Similar to claim 18, each of the claims 19-23 recite either “ESP packet” and/or “ESP packets” which also require clarification and correction.
Claim 23 recites the following limitations:
In lines 3 “the SPI value of the ESP packet is equal to the SPI value of the SA..”
In lines 5 “the source IP address of the at least one ESP packet is the same as the source IP address of the SA,”
In lines 7 “the destination IP address of the at least one ESP packet is the same as the destination IP address of the SA”
In line 9 “the SN of the ESP packets is less than the lower edge of a new anti-replay window…”
There are lack of antecedent basis for these limitations in the claim. Corrections are requested.
Claim 31 recites the following limitations:
In lines 3 “the SPI value of the at least one ESP packet is equal to the SPI value of the SA…”
In lines 5 “the source IP address of the at least one ESP packet is the same as the source IP address of the SA,”
In lines 7 “the destination IP address of the at least one ESP packet is the same as the destination IP address of the SA,”
In lines 9 “the SN of the at least one ESP packet is less than the lower edge of the new anti-replay window.”
There are lack of antecedent basis for these limitations in the claim. Corrections are requested.
Claim Rejections - 35 USC § 102
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the basis for the rejections under this section made in this Office action:
A person shall be entitled to a patent unless –
(a)(1) the claimed invention was patented, described in a printed publication, or in public use, on sale, or otherwise available to the public before the effective filing date of the claimed invention.
Claims 18, 24 and 25 are rejected under 35 U.S.C. 102(a)(1) as being anticipated by Charan et al. (US 2016/0057116), hereinafter Charan.
As for claim 18, Charan teaches a method performed by a communication device (Fig. 30, INE 102 and Red-side Protocol Adapter 201; paragraph [0007] describes a communication apparatus comprises a first protocol adapter; paragraph [0062] describes the Red-side protocol adapter can be software and/or instructions stored on storage medium that is read and executed by processors on an INE), comprising:
determining that an attack on the communication device has occurred, responsive to:
receiving at least a threshold amount of encapsulated security packets (ESPs) with sequence numbers (SNs) that are outside of anti-replay window (paragraphs [0187]-[0191] describe packets in a network are encrypted by an INE using the IPsec tunnel-mode Encapsulating Security Payload (ESP) mechanism. In detecting a replay attack, a protocol adapter may receive a plurality of data packets of the multicast flow from protocol adapter. Each respective data packet may include a respective message in a set of one or more pass-through fields of the respective data packet, wherein the respective message may include a respective sequence number for the respective data packet. The protocol adapter determines whether the respective data packet is one of a duplicate packet or an out of order data packet based at least in part on the respective sequence number. The protocol adapter, responsive to the respective sequence number being less than or equal to the sequence number stored in the multicast anti-replay window of the previously received data packet, the protocol adapter increases a replay attack detection counter by one. The protocol adapter then compares the replay attack detection counter to replay attack detection threshold. Responsive to the replay attack detection counter being greater than or equal to the replay attack threshold, the protocol adapter determines that a replay attack has occurred on the multicast flow), or
receiving an ESP packet with a SN that is a duplicate of a previously received ESP packet (paragraphs [0187]-[0189] describe a protocol adapter receives a plurality of data packets of a multicast flow from another protocol adapter, each of respective message includes a respective sequence number. For each respective data packet of the plurality of data packets, the protocol adapter determines whether the respective data packet is one of a duplicate packet or an out of order data packet based at least in part on the respective sequence number).
As for claim 24, Charan teaches wherein the communication device is configured to support Internet protocol security (IPSec) (paragraph [0057] describes data packets are sent to an IPSEC-based INE).
As for claim 25, Charan teaches wherein the communication device is one of:
a security gateway (paragraph [0046] describes an INE is a secure gateway; paragraphs [0183]-[0184] and [0187] describe a first protocol adapter positioned within a first network, the protocol adapter processes a first data packet, and sends the first data packet to an INE. The first protocol adapter detects a the replay attack. Thus, the first protocol adapter is construed as a security gateway);
a firewall;
a router;
a server;
or a user equipment.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim 19 is rejected under 35 U.S.C. 103 as being unpatentable over Charan (US 2016/0057116), in view of Mortensen et al. (US 2018/0176139), hereinafter Mortensen further in view of Venkatramani et al. (US 8,300,532), hereinafter Venkatramani.
As for claim 19, Charan teaches wherein at least one ESP packet is related to the attack (paragraphs [0190]-[0191] describe the packet that related to a replay attack).
Charan fails to teach
applying an access control list (ACL) to a communication device in response to the attack, the ACL being configured to drop at least one packet.
Mortensen discloses
applying an access control list (ACL) to a communication device in response to the attack (paragraph [0051]-[0054] describe a discard policy typically causes a network policy enforcement device to discard or drop data packets or flows associated with a particular traffic class. A flow analysis engine supports different policies, including discard policies. A discard policy typically causes a network policy enforcement device, such as the attack mitigation device, to discard or drop data packets or flows associated with a particular traffic class. An access control list (ACL) specifies actions to be performed by a network device when predefined conditions are met. The ACL compares a portion of network traffic, e.g., a frame header to one of the conditions. If a conditions is satisfied, ACL instructs the network device to perform corresponding action (i.e. drop the packet). The ACL represents the discarded network traffic information and the traffic discarded as a result of changes is correlated to the discard policy containing traffic discard rules. Such rules is loaded by a network policy enforcement device in response to a DDoS attack detected by the attack mitigation device) , the ACL being configured to drop at least one packet (paragraph [0052] describes if a condition is satisfied, ACL instructs the network device to drop the packet).
One of ordinary skill in the art before the effective filing date of the claimed invention would have recognized the ability to utilize the teachings of Mortensen for applying rules associated with an access control list to a flow analysis engine. The teachings of Mortensen, when implemented in the Charan system, will allow one of ordinary skill in the art to improve classification security in a network. One of ordinary skill in the art would be motivated to utilize the teachings of Mortensen in the Charan system in order to enforce rules to discard or drop data packets or flows when a predefined conditions are met.
The combined system of Charan and Mortensen fails to teach wherein an ACL is applied to a forwarding plane of a device.
Venkatramani discloses
teach wherein an ACL is applied to a forwarding plane of a device (col. 2, lines 21-24 describe a network device includes a forwarding plane to conduct ACL lookups for a packet).
One of ordinary skill in the art before the effective filing date of the claimed invention would have recognized the ability to utilize the teachings of Venkatramani for provide an ACL service to a forwarding plane of a device. The teachings of Venkatramani, when implemented in the Charan and Mortensen system, will allow one of ordinary skill in the art to forward data packets according to ACL. One of ordinary skill in the art would be motivated to utilize the teachings of Venkatramani in the Charan and Mortensen system in order to implement routing instructions from a control plane to forward packet downstream as quickly as possible (Venkatramani: col. 1, lines 23-29).
Claims 26, 32 and 33 are rejected under 35 U.S.C. 103 as being unpatentable over Charan (US 2016/0057116), in view of Armelin et al. (US 12,069,077), hereinafter Armelin.
As for claim 26, Charan teaches a communication device comprising:
at least one processor (Fig. 30, INE 102 and Red-side Protocol Adapter 201; paragraph [0007]-[0008] describe a communication apparatus comprises a first protocol adapter, paragraph [0062] describes the Red-side protocol adapter can be software and/or instructions stored on storage medium that is read and executed by processors on an INE; paragraph [0192] further describe processors); and
at least one memory (paragraphs [0062] and [0193] describes computer-readable storage media), the at least one memory containing instructions executable by the at least one processor (paragraphs [0062] and [0192]-[0194] describe the instructions stored at the storage media is executed by the processors), whereby the communication device is operative to:
when a number of occurrences of an event that a sequence number (SN) of an encapsulating security payload (ESP) packet received by the communication device is outside an anti-replay window, is greater than or equal to a predetermined threshold, or when the SN of an ESP packet received by the communication device is duplicate with the SN of a previously received ESP packet, determine that an attack has occurred on the communication device (paragraphs [0187]-[0191] describe packets in a network are encrypted by an INE using the IPsec tunnel-mode Encapsulating Security Payload (ESP) mechanism. In detecting a replay attack, a protocol adapter may receive a plurality of data packets of the multicast flow from protocol adapter. Each respective data packet may include a respective message in a set of one or more pass-through fields of the respective data packet, the respective message may include a respective sequence number for the respective data packet. The protocol adapter determines whether the respective data packet is one of a duplicate packet or an out of order data packet based at least in part on the respective sequence number. The protocol adapter, responsive to the respective sequence number being less than or equal to the sequence number stored in the multicast anti-replay window of the previously received data packet, the protocol adapter increases a replay attack detection counter by one. The protocol adapter then compares the replay attack detection counter to replay attack detection threshold. Responsive to the replay attack detection counter being greater than or equal to the replay attack threshold, the protocol adapter determines that a replay attack has occurred on the multicast flow).
Charan fails to teach wherein
a data packet is received in a first predetermined time period.
Armelin discloses
a data packet is received in a first predetermined time period (col. 6, lines 43-64 describe a process of counting the number of data packets grouped by the source IP address in a time window period. The collected data is classified based on the number of data packets received by an electronic device per predefined time window indicating a same source IP address; col. 8, lines 8-20 describe the number of messages of a certain type generated by an application per predefined time window are collected).
One of ordinary skill in the art before the effective filing date of the claimed invention would have recognized the ability to utilize the teachings of Armelin for comparing packets received during a predetermined time. The teachings of Armelin, when implemented in the Charan system, will allow one of ordinary skill in the art to improve classification security in a network. One of ordinary skill in the art would be motivated to utilize the teachings of Armelin in the Charan system in order to detect a DDoS attack.
As for claim 32, the combined system of Charan and Armelin teaches wherein the communication device is configured to support Internet protocol security (IPSec) (Charan: paragraph [0057] describes data packets are sent to an IPSEC-based INE).
As for claim 33, the combined system of Charan and Armelin teaches wherein the communication device is one of:
a security gateway (Charan: paragraph [0046] describes an INE is a secure gateway; paragraphs [0183]-[0184] and [0187] describe a first protocol adapter positioned within a first network, the protocol adapter processes a first data packet, and sends the first data packet to an INE. The first protocol adapter detects a the replay attack. Thus, the first protocol adapter is construed as a security gateway);
a firewall;
a router;
a server; or
a user equipment.
Allowable Subject Matter
The following is a statement of reasons for the indication of allowable subject matter:
Prior art fails to teach every limitations recited in claims 20-23 and 27-31. Therefore, claims 20-23 and 27-31 are objected to as being dependent upon a rejected base claim, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims.
As for claim 20, the claim recites the limitations “20. The method according to claim 19, wherein the ACL instructs the forwarding plane to drop the ESP packets satisfying following conditions:
a security parameters index (SPI) value of the ESP packets is equal to the SPI value of a security association (SA) for which the attack is determined to have occurred on the communication device;
a source Internet protocol (IP) address of the ESP packets is the same as the source IP address of the SA;
a destination IP address of the at least one ESP packet is the same as the destination IP address of the SA; and
the SNs of the ESP packets is less than a lower edge of the anti-replay window by which the attack is determined to have occurred on the communication device, or is less than or equal to the duplicate SN.”
Kim et al. (US 2019/0182154) discloses a method for a forwarding element. The method receives a data message with an ACL rule and a first digest for the ACL rule appended to the data message. The ACL rule specifies that the packet is allowed to be sent through the network. The method verifies the ACL rule by computing a second digest from the ACL rule using a secret key and comparing the first digest to the second digest. The method determines whether the packet matches the ACL rule by comparing values in headers of the data message to values specified in the ACL rule. The method only forwards the data message if the ACL rule is verified and the packet matches the ACL rule. The ACL specifies a set of source addresses and destination addresses and compares a source address of the data message to the set of one or more allowed source addresses, a destination address of the data message to the set of one or more allowed destination addresses (cls. 11 and 12).
As for claim 21, the claim recites the limitations “21. The method according to claim 19, further comprising removing the ACL from the forwarding plane responsive to rekeying occurring or the number of ESP packets dropped according to the ACL not increasing over a defined time period.”
Ni et al. (US 2018/0205659) disclose when a forwarding plane device receives an operation request of a service flow processing policy (for example, requesting to install, delete, or modify a policy), the forwarding plane device first obtains, according to a received request message, the identifier of the first control domain and information about the identifier of the service flow that needs to be operated, and performs authentication on the request message according to the pre-obtained correspondence between a control domain identifier and a service flow identifier. If the identifier of the first control domain that is obtained according to a message of the operation request of the service flow processing policy is inconsistent with the recorded control domain identifier corresponding to the service flow identifier, authentication fails. If the identifier of the first control domain that is obtained according to a message of the operation request of the service flow processing policy is consistent with the recorded control domain identifier corresponding to the service flow identifier, authentication succeeds. The forwarding plane device installs, deletes, or modifies the service flow processing policy according to the request message (see paragraphs [0052] and [0058]). Ni discloses a process of deleting a service flow processing policy based on the validity of a control domain identifier and a success authentication. Ni, however, fails to teach what were claimed.
As for claim 22, the claim recites the limitations “22. The method according to claim 19, further comprising updating the ACL in response to detecting a new attack, the updated ACL being configured to drop ESP packets related to the attack as previously determined, and related to the new attack.”
Jeong et al. (US 2023/0103979) disclose a policy reconfiguration rearranges a security policy in a different form or combination of the existing security policy to enhance the security service in a network. The policy reconfiguration is generated by the analyzer after receiving and analyzing monitoring data of NSF events. The analyzer generates a new policy to handle the DDoS attack as a firewall rule to drop all packets from the source of the DDoS attack (see paragraphs [0112] and [0118]).
As for claim 23, the claim recites the limitations “23. (New) The method according to claim 22, wherein the updated ACL is updated to add instructions for dropping ESP packets that satisfy the following conditions:
the SPI value of the ESP packets is equal to the SPI value of the SA for which the new attack is determined to have occurred on the communication device;
the source IP address of the at least one ESP packet is the same as the source IP address of the SA;
the destination IP address of the at least one ESP packet is the same as the destination IP address of the SA; and
the SN of the ESP packets is less than the lower edge of a new anti-replay window by which the new attack is determined to have occurred on the communication device, or is less than or equal to a new duplicate SN detected for the new attack.”
The claim is dependent claim of claim 22 which is being dependent upon a rejected base claim 19.
As for claim 27, the claim recites the limitations “27. (New) The communication device according to claim 26, wherein the communication device is further operative to:
when determining that an attack has occurred on the communication device, determine an access control list (ACL) that is to be applied to a forwarding plane of the communication device to drop at least one ESP packet related to the attack, based on the anti-replay window by which the attack is determined to have occurred on the communication device or based on the duplicate SN; and
apply the ACL to the forwarding plane.”
Similar to claim 19, the combination of Mortensen (US 2018/0176139) and Venkatramani (US 8,300,532) teaches some of the limitations recited in the claim but not all of the limitations.
As for claim 28, the claim recites the limitations “28. The communication device according to claim 27, wherein the ACL instructs the forwarding plane to drop at least one ESP packet satisfying following conditions:
a security parameters index (SPI) value of the at least one ESP packet is equal to the SPI value of a security association (SA) for which the attack is determined to have occurred on the communication device;
a source Internet protocol (IP) address of the at least one ESP packet is the same as the source IP address of the SA;
a destination IP address of the at least one ESP packet is the same as the destination IP address of the SA; and
the SN of the at least one ESP packet is less than a lower edge of the anti-replay window by which the attack is determined to have occurred on the communication device, or is less than or equal to the duplicate SN.”
As for claim 29, the claim recites the limitations “29. The communication device according to claim 27, wherein the communication device is further operative to:
when a number of ESP packets dropped by the forwarding plane according to the ACL does not increase in a second predetermined time period, or when rekeying occurs, remove the ACL from the forwarding plane.
As for claim 30, the claim recites the limitations “30. The communication device according to claim 27, wherein the communication device is further operative to:
when determining that a new attack different than a previous attack has occurred on the communication device, determine an updated ACL, that is to be applied to the forwarding plane to drop at least one ESP packet related to both the new attack and the previous attack, based on a new anti-replay window by which the new attack is determined to have occurred on the communication device or based on a new duplicate SN; and
apply the updated ACL to the forwarding plane.”
As for claim 31, the claim recites the limitations “31. The communication device according to claim 30, wherein the updated ACL instructs the forwarding plane to drop at least one ESP packet satisfying following conditions:
the SPI value of the at least one ESP packet is equal to the SPI value of the SA for which the new attack is determined to have occurred on the communication device;
the source IP address of the at least one ESP packet is the same as the source IP address of the SA;
the destination IP address of the at least one ESP packet is the same as the destination IP address of the SA; and
the SN of the at least one ESP packet is less than the lower edge of the new anti-replay window by which the new attack is determined to have occurred on the communication device, or is less than or equal to the new duplicate SN.”
As allowable subject matter has been indicated, applicant's reply must either comply with all formal requirements or specifically traverse each requirement not complied with. See 37 CFR 1.111(b) and MPEP § 707.07(a).
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure.
Shen et al. (US 2023/0188469) teach methods for automatic adjusting a time-based anti-replay window size
Rotvold et al. (US 2023/0094500) teach process installation network intrusion detection and prevention
Vukovic et al. (US 8,438,641) teach security protocol processing for anti-replay protection
Aimangala Nagaraja Setty (US 2022/021020) teach dynamic adaptation of ARW management with enhanced security.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to L. T N. whose telephone number is (571)272-1013. The examiner can normally be reached M & Th 5:30 am - 2:30 pm EST.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, TONIA DOLLINGER can be reached at 571-272-4170. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/L. T. N/
Examiner, Art Unit 2459
/TONIA L DOLLINGER/Supervisory Patent Examiner, Art Unit 2459