DETAILED ACTION
Continued Examination Under 37 CFR 1.114
A request for continued examination under 37 CFR 1.114, including the fee set forth in 37 CFR 1.17(e), was filed in this application after final rejection. Since this application is eligible for continued examination under 37 CFR 1.114, and the fee set forth in 37 CFR 1.17(e) has been timely paid, the finality of the previous Office action has been withdrawn pursuant to 37 CFR 1.114. Applicant's submission filed on 08/06/26 has been entered.
Response to Amendment
The amendment filed on 08/06/26 has been entered. Claims 1-2, 4-9, 11-12 are pending in the application.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claims 1-2, 4 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Independent claim 1 recites a system for querying large provenance graph repositories comprising: a server; a processor; and a memory storing instructions, which when executed by the processor, cause the processor to apply a graph simplification including a system directory-based abstraction, wherein the graph simplification includes an abstraction which is configured to merge object nodes including at least one of files, network sockets, and registry entries into a merged object node, apply an embedding function, and apply a subgraph prediction function, and provide a prediction as to whether a first k-hop ego-graph centered around a process node is a subgraph of a second k-hop ego-graph centered around a process node of an original provenance graph, wherein the original provenance graph comprises a set of nodes representing system entities and a set of directed edges representing flows of information between the system entities, wherein each node is associated with a node type, and wherein each directed edge is associated with an edge type, an event type, and a timestamp, wherein the embedding function is a learned function that utilizes an inductive graph neural network with an order embedding technique and a max-margin loss, and wherein the embedding function is: n_Gp -> Rd, that maps each ego-graph Gp(GpcG) to a d-dimensional representation z E Rd, where, GP: a k-hop ego-graph centered around node p, g: a original provenance graph, Rd: a d-dimensional real vector space, and z: a d-dimensional embedding vector corresponding to the ego-graph Gp.
The limitations of apply a graph simplification including a system directory-based abstraction, wherein the graph simplification includes an abstraction which is configured to merge object nodes including at least one of files, network sockets, and registry entries into a merged object node, apply an embedding function, and apply a subgraph prediction function, and provide a prediction as to whether a first k-hop ego-graph centered around a process node is a subgraph of a second k-hop ego-graph centered around a process node of an original provenance graph, wherein the original provenance graph comprises a set of nodes representing system entities and a set of directed edges representing flows of information between the system entities, wherein each node is associated with a node type, and wherein each directed edge is associated with an edge type, an event type, and a timestamp, wherein the embedding function is a learned function that utilizes an inductive graph neural network with an order embedding technique and a max-margin loss, wherein the original provenance graph comprises a set of nodes representing system entities and a set of directed edges representing flows of information between the system entities, wherein each node is associated with a node type, and wherein each directed edge is associated with an edge type, an event type, and a timestamp and wherein the embedding function is: n_Gp -> Rd, that maps each ego-graph Gp(GpcG) to a d-dimensional representation z E Rd, where, GP: a k-hop ego-graph centered around node p, g: a original provenance graph, Rd: a d-dimensional real vector space, and z: a d-dimensional embedding vector corresponding to the ego-graph Gp, as drafted, are processes that, under their broadest reasonable interpretation, cover mental processes and mathematical formulas/relationships but from the recitation of implementing them on generic computer components. These additional steps are considered an abstract idea (mental process and mathematical concepts) and do not integrate the judicial exception into a practical application. The “apply a graph simplification” limitation encompasses the user judging an abstraction by judging a merging of object nodes comprising entries. Additionally, this limitation only limits that the abstraction “is configured to merge” and does not recite this as an affirmative step. Further, the “apply an embedding function and subgraph prediction function” steps as well as the wherein clauses for the embedding function are directed to mathematical formulas/relationships while the limitation “and provide” encompasses a mere judgement. Lastly, the “wherein the original provenance graph” limitation does not preclude the limitation pertaining to “provide a prediction” from being directed to a mental process step (judgement). If a claim limitation, under its broadest reasonable interpretation, covers judgments and mathematical relationships and/or formulas, then it falls within the “Mental Process” and “Mathematical Concepts” groupings of abstract ideas, respectively. Accordingly, claim 1 recites an abstract idea (Step 2A, Prong 1).
This judicial exception is not integrated into a practical application. In particular, the claim recites the additional elements of – a system for querying large provenance graph repositories comprising: a server; a processor; and a memory storing instructions, which when executed by the processor, cause the processor to apply an embedding function, and apply a subgraph prediction function, wherein the embedding function is a learned function that utilizes an inductive graph neural network with an order embedding technique and a max-margin loss, and wherein the embedding function is: n_Gp -> Rd, that maps each ego-graph Gp(GpcG) to a d-dimensional representation z E Rd, where, GP: a k-hop ego-graph centered around node p, g: a original provenance graph, Rd: a d-dimensional real vector space, and z: a d-dimensional embedding vector corresponding to the ego-graph Gp. The system, processor, server, and memory are recited at a high-level of generality (i.e., as generic computer devices performing generic computer functions) and do not meaningfully limit the claim. The claim does not include any further additional elements. Further, these limitations are recited as being performed using generic computing components at a high level of generality. That is, the limitation pertaining to “utilizes an inductive graph neural network”, computing components are used as a tool to perform the generic computer function of being a learned function. See MPEP 2106.05(f). In the limitation pertaining to “the embedding function”, the computer is used to perform an abstract idea, as discussed above in Step 2A, Prong One, such that it amounts to no more than mere instructions to apply the exception using a generic computer. See MPEP 2106.05(f). The judicial exception of “the embedding function” is performed utilizing “an inductive graph neural network”. The inductive graph neural network is used to generally apply the abstract idea without placing any limits on how the learned function utilizes the inductive graph neural network. The recitation of “utilizing “an inductive graph neural network” in the limitations also merely indicates a field of use or technological environment in which the judicial exception is performed. Although the additional element “utilizing “an inductive graph neural network” limits the identified judicial exception of applying the embedding function, this type of limitation merely confines the use of the abstract idea to a particular technological environment (neural networks) and thus fails to add an inventive concept to the claims. See MPEP 2106.05(h). Accordingly, these additional elements, individually and in combination, do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea (Step 2A, Prong 2).
The claims do not include any additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements represent further mental process steps. In the limitation pertaining to “the embedding function”, the computer is used to perform an abstract idea, as discussed above in Step 2A, Prong One, such that it amounts to no more than mere instructions to apply the exception using a generic computer. See MPEP 2106.05(f). The additional elements pertaining to the embedding function being a learned function that utilizes an inductive graph neural network was both found to be insignificant extra-solution activity in Step 2A, Prong Two. The additional elements merely recite generic computing devices performing generic computing functions which are not further limiting, and thus, do not cause the claim to amount to significantly more than the judicial exception. (Step 2B). Accordingly, claims 1 is not patent eligible.
Claims 2, 4 depend on claim 1 and include all the limitations of these claims. Therefore, these claims are directed to the same abstract idea and the analysis must proceed to (Step 2A, Prong 2).
Claim 2 recites additional limitations pertaining to the server receiving kernel logs. These additional limitations do not integrate the abstract idea into a practical application and merely represent insignificant extra-solution activities to the judicial exception and are mere data gathering steps. Accordingly, these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea.
The claims do not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements represent well-understood, routine, conventional activity previously known to the industry. That is, these limitations represent well-understood, routine, conventional activity in the fields of data processing and/or data storage and retrieval and are merely directed to the well-understood, routine, conventional activity of storing and retrieving information in memory, Versata Dev. Group, Inc. v. SAP Am., Inc., 793 F.3d 1306, 1334, 115 USPQ2d 1681, 1701 (Fed. Cir. 2015) and receiving or transmitting data over a network, e.g., using the Internet to gather data, Symantec, 838 F.3d at 1321, 120 USPQ2d at 1362 (utilizing an intermediary computer to forward information). Therefore, these additional elements do not cause the claim to amount to significantly more than the judicial exception.
Claim 4 recites additional limitations pertaining to the subgraph prediction function. This judicial exception is not integrated into a practical application. The additional elements represent further mathematical relationships/formulas. If a claim limitation, under its broadest reasonable interpretation, covers mathematical relationships/formulas but for the recitation of generic computer components, then it falls within the “Mathematical Concepts” grouping of abstract ideas. This additional step is considered an abstract idea and does not integrate the judicial exception into a practical application.
The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional elements represent further mathematical concepts. Therefore, these additional limitations are not sufficient to amount to significantly more than the judicial exception. Claim 4 is not patent eligible.
Response to Arguments
The following is in response to the amendment filed on 08/06/26.
Applicant’s arguments have been carefully and respectfully considered but are not persuasive.
Regarding 35 USC 101, on pgs. 8-9, applicant argues that the limitations including the newly amended portions are not directed to an abstract embedding or prediction, but instead recites the use of a particular typed, even-based timestamped provenance-graph representation and process-centered k-hop ego-graph in a specific computer-implemented provenance graph search architecture.
In response to the preceding argument, examiner respectfully submits that the limitations including the amended portions still recite an abstract idea, and, the amended portions do not preclude this step from being directed to a mental process step (judgement). Further, the amended limitation pertaining to what the original provenance graph comprises also do not preclude this step from being performed mentally. Lastly, the computer-implemented provenance-graph search architecture comprises generic computing components performing generic computing functions. Therefore, this additional limitation would not implement the judicial exception into a practical application, nor would it provide significantly more.
Regarding 35 USC 101, on pg. 9, applicant argues that the amended claims integrate any alleged judicial exception into a practical application under step 2A, Prong Two, do not merely collect information and apply a mathematical relationship, and rather, impose meaningful technological constraints and the embedding and subgraph prediction functions are not claimed in isolation and operation on the provenance-graph structures and process-centered k-hop ego-graphs.
In response to the preceding argument, examiner respectfully submits that the manner in which the provenance-graph structures and process-centered k-hop ego-graphs are defined in the claim does not necessarily tie them to specific data structures stored within memory or the computing device. Further, the claim is silent with regard to how the prediction is actually made by the system using these graphs.
Regarding 35 USC 101, on pgs. 9-10, applicant argues that the features define how the computer organizes system-level activity into a provenance graph and how the system partitions and processes that graph for subgraph searching. Thus, the claims are directed to a practical application that improves the manner in which large provenance graph repositories are queried.
In response to the preceding argument, examiner respectfully submits that claim 1 does not recite any limitations pertaining to partitioning the graph, specifically, nor does it even recite receiving or executing a query which comprises the steps as already claimed. MPEP 2106.05(a) states that “after the examiner has consulted the specification and determined that the disclosed invention improves technology, the claim must be evaluated to ensure the claim itself reflects the disclosed improvement in technology.”.
Regarding 35 USC 101, on pg. 10, applicant argues that the claims recite significantly more than the alleged judicial exception under step 2B, makes provenance-graph searching more efficient when considered as a whole, and the improvement is recognized as eligible in cases such as Enfish.
In response to the preceding argument, examiner respectfully submits that the additional limitations pertaining to the graphs do not even tie to their actual storage or data structure within memory or a computing device. This abstraction of data could be realized mentally by a user such that a prediction (judgement) could be reasonably made. Therefore, the usage of these graphs to provide a prediction do not provide significantly more than the judicial exception. Further, as stated in the rejection, the limitation pertaining to “wherein the graph simplification includes an abstraction which is configured to” only limits that the abstraction “is configured to merge” and does not recite this as an affirmative step.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to WILLIAM P BARTLETT whose telephone number is (469)295-9085. The examiner can normally be reached on M-Th 11:30-8:30, F 11-3.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Sherief Badawi can be reached on 571-272-9782. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/WILLIAM P BARTLETT/
Primary Examiner, Art Unit 2169