DETAILED ACTION
Notice of Pre-AIA or AIA Status.
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
1. The text of those sections of Title 35 U.S.C not included in this section can be found in the prior office action.
2. The prior office actions are incorporated herein by reference. In particular, the observations with respect to claim language, and response to previously presented arguments.
Claim 19 has been amended.
No claims have been added.
No claims have been cancelled.
Claims 1-20 are pending.
Response to Arguments
The terminal disclaimer filed on 04/28/2026 is acknowledged and approved. Therefore, the claim DP rejections have been withdrawn.
With regards to prior art rejection of claim 1, Applicant argues “receiving data, as described by Symon, is not equivalent to "receiving first information associated with a first plurality of files associated with a first organization," as claimed. Symon's generic description of receiving data does not specify what kind of data is received or any organization that the data is associated with. And Symon especially does not disclose that the received data is associated with a first plurality of files.
Further, training a machine learning detection model for a device using network flows that have been labeled as "normal" or "attack," as described by Symon, is not equivalent to "based on the first information and second information associated with a second plurality of files associated with a second organization, training a machine learning model usable by the second organization for classifying files," as claimed. As an initial matter, Symon's machine learning detection model is trained to detect network intrusions-not to classify files.
Examiner respectfully disagrees and asserts the under the broadest reasonable interpretation of the claim, the received data could be in form of data files transmitted from a source (e.g., a first organization). Also, the “support or the IT team” in the reference examining the data traffic could be interpreted as the second organization. As for classifying file, detecting intrusion is basically identifying certain data (e.g., data files) that are classified as unwanted. Therefore, Applicant’s argument is not persuasive.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-20 are rejected under 35 U.S.C. 103 as being unpatentable over Christopher T. Symons US 20150067857 (hereinafter Symon) in view of Xian- Sheng Hua US 20160217349 (hereinafter Hua).
As per claim 1, Symons teaches: A method comprising: receiving first information associated with a first plurality of files associated with a first organization ("The physical or external process is defined by the computing session in which data is received and/or processed or during the time in which a program is running that begins when the data is received" Symons: para. 41);
based on the first information and second information associated with a second plurality of files associated with a second organization, training a machine learning model usable by the second organization for classifying files ("The device may identify a sufficient (small) number of network flows that are normal and benign activities on their network. In training a red-teaming is performed by either the support or IT team to provide examples of a small number of attacks of the type they want to identify. For example, maybe they don't want the device to alert on probes, only on exploits, so they use a variety of exploits run against the network. These known behaviors, the normals, and the attacks, are labeled as such for the device, and the machine-learning detection model for the device is then trained either on a separate, more powerful machine, or on the device itself The deployed device then uses this model to make alerting decisions." Symons: para. 40);
Symons does not teach; however, Hua discloses: causing output, by the trained machine learning model, of a classification of at least one file associated with the second organization ("the classifying module 120 may compare the second label resulting from classification with the first label associated with the new positive multimedia data item. Based at least in part on identifying the misclassification, the updating module 208 may adjust at least some of the model vectors. For instance, if the classifying module 120 determines that the new positive multimedia data item is incorrectly classified as the second label, the updating module 208 may scale down the model vector associated with the second label and may scale up the model vector associated with the first label." Hua: para. 58).
Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify Symons with the teaching of Hua to meet the preceding limitations. One of ordinary skill in the art would have been motivated to make such modification since such techniques were known at the time of the instant invention and would be applied to further refine the classifier (Hua para. 58).
As per claim 2, the rejection of claim 1 is incorporated herein. Symons does not teach; however, Hua discloses: the first information comprises a first feature vector representation of the first plurality of files, and wherein the first feature vector representation comprises non-sensitive data associated with the first organization (Hau: para. 97).
As per claim 3, the rejection of claim 1 is incorporated herein. Symons teaches: the first plurality of files is associated with a first plurality of adjudicated classifications ("In training a red-teaming is performed by either the support or IT team to provide examples of a small number of attacks of the type they want to identify. For example, maybe they don't want the device to alert on probes, only on exploits, so they use a variety of exploits run against the network." Symons: para. 40).
As per claim 4, the rejection of claim 1 is incorporated herein. Symons teaches: the training uses at least a portion of each of the first information and the second information to form a training data set, the method further comprising: receiving an indication of an amount of each portion of each of the first information and the second information to be used in the training data set ("Selected semi-supervised learning may depend on the choice of features, choice of event definition, etc. In this disclosure an event is any collection of features that quantify what has occurred in a network, on a host, etc. over a specified period of time. The time period may be an n-second time window or may be based on the period in which a network connection is sustained." Symons: para. 14).
As per claim 5, the rejection of claim 1 is incorporated herein. Symons teaches: the first information indicates at least one of a file header property, a component of a file, or a binary sequence (Symons: para. 30).
As per claim 6, this claim defines a computing device that corresponds to the method of claim 1 and does not define beyond limitations of claim 1. Therefore, claim 6 is rejected with the same rational as in the rejection of claim 1.
As per claim 7, this claim defines a computing device that corresponds to the method of claim 2 and does not define beyond limitations of claim 2. Therefore, claim 7 is rejected with the same rational as in the rejection of claim 2.
As per claim 8, this claim defines a computing device that corresponds to the method of claim 3 and does not define beyond limitations of claim 3. Therefore, claim 8 is rejected with the same rational as in the rejection of claim 3.
As per claim 9, this claim defines a computing device that corresponds to the method of claim 4 and does not define beyond limitations of claim 4. Therefore, claim 9 is rejected with the same rational as in the rejection of claim 4.
As per claim 10, this claim defines a computing device that corresponds to the method of claim 5 and does not define beyond limitations of claim 5. Therefore, claim 10 is rejected with the same rational as in the rejection of claim 5.
As per claim 11, this claim defines a computer-readable storage medium storing computer-readable instruction that corresponds to the method of claim 1 and does not define beyond limitations of claim 1. Therefore, claim 11 is rejected with the same rational as in the rejection of claim 1.
As per claim 12, this claim defines a computer-readable storage medium storing computer-readable instruction that corresponds to the method of claim 2 and does not define beyond limitations of claim 2. Therefore, claim 12 is rejected with the same rational as in the rejection of claim 2.
As per claim 13, this claim defines a computer-readable storage medium storing computer-readable instruction that corresponds to the method of claim 3 and does not define beyond limitations of claim 3. Therefore, claim 13 is rejected with the same rational as in the rejection of claim 3.
As per claim 14, this claim defines a computer-readable storage medium storing computer-readable instruction that corresponds to the method of claim 4 and does not define beyond limitations of claim 4. Therefore, claim 14 is rejected with the same rational as in the rejection of claim 4.
As per claim 15, this claim defines a computer-readable storage medium storing computer-readable instruction that corresponds to the method of claim 5 and does not define beyond limitations of claim 5. Therefore, claim 15 is rejected with the same rational as in the rejection of claim 5.
As per claim 16, Symons teaches: A system comprising: receive first information associated with a first plurality of files associated with a first organization ("The physical or external process is defined by the computing session in which data is received and/or processed or during the time in which a program is running that begins when the data is
received" Symons: para. 41);
based on the first information and second information associated with a second
plurality of files associated with a second organization, train a machine learning model
usable by the second organization for classifying files ("The device may identify a
sufficient (small) number of network flows that are normal and benign activities on their
network. In training a red-teaming is performed by either the support or IT team to
provide examples of a small number of attacks of the type they want to identify. For
example, maybe they don't want the device to alert on probes, only on exploits, so they
use a variety of exploits run against the network. These known behaviors, the normals,
and the attacks, are labeled as such for the device, and the machine-learning detection
model for the device is then trained either on a separate, more powerful machine, or on
the device itself The deployed device then uses this model to make alerting decisions."
Symons: para. 40);
at least one second computer device configured to:
send, to the at least one first computing device, the first information ("The physical or external process is defined by the computing session in which data is received and/or processed or during the time in which a program is running that begins when the data is received." Symons: para. 41).
Symons does not teach; however, Hua discloses: cause output, by the trained
machine learning model, of a classification of at least one file associated with the
second organization ("the classifying module 120 may compare the second label
resulting from classification with the first label associated with the new positive multimedia data item. Based at least in part on identifying the misclassification, the
updating module 208 may adjust at least some of the model vectors. For instance, if the
classifying module 120 determines that the new positive multimedia data item is
incorrectly classified as the second label, the updating module 208 may scale down the
model vector associated with the second label and may scale up the model vector
associated with the first label." Hua: para. 58).
Therefore, it would have been obvious to one of ordinary skill in the art before the
effective filing date of the claimed invention to modify Symons with the teaching of Hua
to meet the preceding limitations. One of ordinary skill in the art would have been
motivated to make such modification since such techniques were known at the time of
the instant invention and would be applied to further refine the classifier (Hua para. 58).
As per claim 17, the rejection of claim 16 is incorporated herein. Symons does
not teach; however, Hua discloses: the first information comprises a first feature vector
representation of the first plurality of files, and wherein the first feature vector
representation comprises non-sensitive data associated with the first organization (Hau:
para. 97).
As per claim 18, the rejection of claim 16 is incorporated herein. Symons
teaches: the first plurality of files is associated with a first plurality of adjudicated
classifications ("In training a red-teaming is performed by either the support or IT team
to provide examples of a small number of attacks of the type they want to identify. For
example, maybe they don't want the device to alert on probes, only on exploits, so they
use a variety of exploits run against the network." Symons: para. 40).
As per claim 19, the rejection of claim 16 is incorporated herein. Symons teaches: the training uses at least a portion of each of the first information and the second information to form a training data set, wherein the at least one first computing device is further configured to: receive an indication of an amount of each portion of each of the first information and the second information to be used in the training data set ("Selected semi- supervised learning may depend on the choice of features, choice of event definition, etc. In this disclosure an event is any collection of features that quantify what has occurred in a network, on a host, etc. over a specified period of time. The time period may be an n-second time window or may be based on the period in which a network connection is sustained." Symons: para. 14).
As per claim 20, the rejection of claim 16 is incorporated herein. Symons teaches: the first information indicates at least one of a file header property, a component of a file, or a binary sequence (Symons: para. 30).
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to GHODRAT JAMSHIDI whose telephone number is (571)270-1956. The examiner can normally be reached 10:00-6:00.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached at 5712723862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/GHODRAT JAMSHIDI/Primary Examiner, Art Unit 2493