DETAILED ACTION
This Office Action has been issued in response to Applicant's Amendment filed May 15, 2026.
Claims 1, 2, 5-7, 9, 10, 14, 15, 17, and 18 have been amended. Claims 21-24 have been added. Claims 3, 4, 11, and 12 have been cancelled.. Claims 1, 2, 5-10, and 13-24 have been examined and are pending.
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 112
The following is a quotation of the first paragraph of 35 U.S.C. 112(a):
(a) IN GENERAL.—The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor or joint inventor of carrying out the invention.
The following is a quotation of the first paragraph of pre-AIA 35 U.S.C. 112:
The specification shall contain a written description of the invention, and of the manner and process of making and using it, in such full, clear, concise, and exact terms as to enable any person skilled in the art to which it pertains, or with which it is most nearly connected, to make and use the same, and shall set forth the best mode contemplated by the inventor of carrying out his invention.
Claims 1, 2, 5-10, and 13-24 are rejected under 35 U.S.C. 112(a) or 35 U.S.C. 112 (pre-AIA ), first paragraph, as failing to comply with the written description requirement. The claim(s) contains subject matter which was not described in the specification in such a way as to reasonably convey to one skilled in the relevant art that the inventor or a joint inventor, or for applications subject to pre-AIA 35 U.S.C. 112, the inventor(s), at the time the application was filed, had possession of the claimed invention. The independent claims recite “mitigates the security vulnerability by dividing the first node into a first group of nodes representing resources accessible using a second key different from the first key and the second node into a second group of nodes representing resources accessible using a third key different from the first key.” Examiner was unable to find support for this in the specification. Paragraph [0053] of applicant’s specification discloses “mitigator 208 divides secrets and/or other secret data that are accessible utilizing a single token in a manner that fewer instances of secrets and/or other secret data are accessible utilizing the same token.” However, this does not appear to support the specific embodiment claimed.
Claim Rejections - 35 USC § 101
In view of applicant’s amendments the pending claim rejections under 35 USC § 101 have been withdrawn.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
The factual inquiries for establishing a background for determining obviousness under 35 U.S.C. 103 are summarized as follows:
1. Determining the scope and contents of the prior art.
2. Ascertaining the differences between the prior art and the claims at issue.
3. Resolving the level of ordinary skill in the pertinent art.
4. Considering objective evidence present in the application indicating obviousness or nonobviousness.
This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention.
Claims 1, 2, 5-10, and 13-24 are rejected under 35 U.S.C. 103 as being unpatentable over US Pub. No. 2025/0373645 to Kumar et al. (hereinafter “Kumar”) and further in view of US Pat. No. 11785051 to Rossman et al. (hereinafter “Rossman”).
As to Claim 1, Kumar discloses a security system of a network-based computing system, comprising: a processor; and a memory comprising program code comprising:
a graph generator that:
generates a graph representative of resources in the network-based computing system, the graph comprising a first node representing a first resource, a second node representing a second resource, a third node, a first edge between the first and third nodes representing an attack path between the first and third nodes, and a second edge between the second and third nodes representing a second attack path between the second and third nodes (Paragraph [0525] of Kumar discloses the security graph may include a plurality of nodes representing entities of a compute environment and a plurality of edges interconnecting the nodes to represent relationships between the entities);
a graph reducer that:
determines a level of structural similarity between the first node and the second node satisfies a structural similarity criterion, and groups the first node and the second node together in a grouped node, resulting in a modified graph (Paragraph [0167] of Kumar discloses a total of three different etcdct1 processes were executed during the 9 am-10 am window, and were clustered together (260). FIG. 2H also depicts two different clusters that are both named etcd2. The first cluster includes (for the 9 am-10 am window) five members (261) and the second cluster includes (for the same window) eight members (262). The reason for these two distinct clusters is that the two groups of applications behave differently (e.g., they exhibit two distinct sets of communication patterns). Specifically, the instances of etcd2 in cluster 261 only communicate with locksmithct1 (263) and other etcd2 instances (in both clusters 261 and 262). The instances of etcd2 in cluster 262 communicate with additional entities, such as etcdct1 and Docker containers); and
an attack path identifier that:
identifies a security vulnerability of the network-based computing system based on the modified graph, [the security vulnerability indicating resources represented by the first grouped node are accessible using a first key corresponding to the first node and
mitigates the security vulnerability by dividing the first node into a first group of nodes representing resources accessible using a second key different from the first key and the second node into a second group of nodes representing resources accessible using a third key different from the first key] (Paragraph [0537] of Kumar discloses attack paths may be identified from security graphs 600, prioritized, and provided on a landing page. Thus, the landing page may present top risks across a security posture. Paragraph [0552] of Kumar discloses Where the risk score is determined based on information associated with a security graph 600, the security graph 600 may be used to present evidence of reasons for a determined risk score, which may help a user understand the reasons for a risk score and how to address the risk factors that made up the risk score. This helps users readily determine how to prioritize their workflows to mitigate risk effectively).
Kumar does not explicitly disclose an edge being an attack path. However, such a feature would have been obvious in view of Kumar. Paragraph [0543] of Kumar discloses the security graph 600 may pivot to focus on something associated with the edge, such as a policy or vulnerability associated with the edge. Paragraph [0536] of Kumar discloses attack paths for internet exposed compute instances with critical vulnerabilities. Accordingly, the edges of Kumar have associated vulnerabilities, and the vulnerabilities are representative of attack paths.
Kumar does not explicitly disclose the security vulnerability indicating resources represented by the first grouped node are accessible using a first key corresponding to the first node and mitigates the security vulnerability by dividing the first node into a first group of nodes representing resources accessible using a second key different from the first key and the second node into a second group of nodes representing resources accessible using a third key different from the first key.
However, Rossman discloses this. Column 5 lines 45-55 of Rossman disclose determine alerts on credential cluster vulnerabilities, such as a weakest link credential, over-scoping of permissions, privilege escalation, exploitation of trust relationships, over-scoping of access to the credential clusters, long lived credentials protecting short lived credentials, etc. Column 5 lines 50-60 of Rossman disclose identity ecosystem analyzer 150 can make recommendations regarding scoping of permissions between related credentials, a need for multi-factor authentication, a need for quorum based authorization, a change in credential rotation policy (e.g., more or less time), etc.
It would have been obvious to one of ordinary skill in the art before the effective filing of the invention to combine the security analysis system as disclosed by Kumar, with adjusting permissions as disclosed by Rossman. One of ordinary skill in the art would have been motivated to combine to apply a known technique to a known device ready for improvement to yield predictable results. Kumar and Rossman are directed toward security analysis systems and as such it would be obvious to use the techniques of one in the other. Column 4 lines 1-20 of Rossman disclose identity ecosystem analyzer 150 can perform a blast radius estimation where, for a given credential, identity ecosystem analyzer 150 can identify any resources that could be compromised directly (i.e., that can be accessed using that credential via one “hop”), as well as indirectly (i.e., multiple hops, such as using the credential to change a policy to allow access to a new resource). The blast radius estimation can further identify a number of points of access, the occurrence of identity federation, any unusually highly credentialed users, or any unused or infrequently used credentials. The blast radius estimation can further identify, for any permission policy, the credentials and resources to which the policy permits access, as well as other metrics such as a shortest access path, cluster connectivity, outliers and edges, distance, amplifiers/influencers, or other measures of centrality.
As to Claim 2, Kumar-Rossman discloses the system of claim 1, wherein the graph reducer further: groups the first and second edges as a grouped edge (Paragraph [0167] of Kumar discloses a total of three different etcdct1 processes were executed during the 9 am-10 am window, and were clustered together (260). FIG. 2H also depicts two different clusters that are both named etcd2. The first cluster includes (for the 9 am-10 am window) five members (261) and the second cluster includes (for the same window) eight members (262). The reason for these two distinct clusters is that the two groups of applications behave differently (e.g., they exhibit two distinct sets of communication patterns). Specifically, the instances of etcd2 in cluster 261 only communicate with locksmithct1 (263) and other etcd2 instances (in both clusters 261 and 262). The instances of etcd2 in cluster 262 communicate with additional entities, such as etcdct1 and Docker containers).
As to Claim 5, Kumar-Rossman discloses the system of claim 1, wherein to determine the level of structural similarity between the third node and the second node, the graph reducer: generates a first sparse vector based on a property of the third node and the second edge; generates a second sparse vector based on a property of the second node and the first edge; and determines a distance between the first sparse vector and the second sparse vector satisfies the structural similarity criterion (Paragraph [0211] of Kumar discloses clustering, described in more detail below, include performing Matching Neighbor clustering and similarity (e.g., SimRank) clustering).
As to Claim 6, Kumar-Rossman discloses the system of claim 1, wherein the graph reducer further: determines a level of structural similarity between the third node and a fourth node fails to satisfy the structural similarity criterion; determines a cardinality of the modified graph fails to satisfy a cardinality criterion; adjusts the structural similarity criterion, resulting in a modified structural similarity criterion; determines the level of structural similarity between the third node and the fourth node satisfies the modified structural similarity criterion; groups the fourth node, the second node, and the third node in the grouped node resulting in the modified graph; and determines the cardinality of the modified graph satisfies the cardinality criterion (Paragraph [0232] of Kumar discloses As a result of performing MNC, SimRank, and cluster splitting (e.g., CmdType splitting) many processes are clustered together based on commonality of behavior (e.g., communication behavior) and commonality of application type. Such clustering represents a significant reduction in graph size (e.g., compared to the original raw physical graph). Nonetheless, further clustering can be performed (e.g., by iterating on the graph data using the GBM to achieve such a polygraph). As more information within the graph is correlated, more nodes can be clustered together, reducing the size of the graph, until convergence is reached and no further clustering is possible).
As to Claim 7, Kumar-Rossman discloses the system of claim 6, wherein the structural similarity criterion specifies a similarity threshold indicative of nodes that share a type and a property and to adjust the structural similarity criterion, the graph reducer: adjusts the similarity threshold to be indicative of nodes that share the type but do not share the property (Paragraph [0214] of Kumar discloses for any two nodes that are members of a given CmdType. Nodes with a threshold amount of commonality. Paragraph [0226] of Kumar discloses SimRank can be modified to use different thresholds.).
As to Claim 8, Kumar-Rossman discloses the system of claim 1, wherein the attack path identifier further: causes an indication of the security vulnerability to be presented in a user interface of a computing device, the indication indicating an entry point of the security vulnerability (Paragraph [0537] of Kumar discloses attack paths may be identified from security graphs 600, prioritized, and provided on a landing page. Thus, the landing page may present top risks across a security posture. Paragraph [0552] of Kumar discloses Where the risk score is determined based on information associated with a security graph 600, the security graph 600 may be used to present evidence of reasons for a determined risk score, which may help a user understand the reasons for a risk score and how to address the risk factors that made up the risk score. This helps users readily determine how to prioritize their workflows to mitigate risk effectively).
As to Claim 9, Kumar discloses a method for mitigating security vulnerabilities in a network-based computing system, the method comprising:
generating a graph representative of resources in the network-based computing system, the graph comprising nodes representative of the resources and edges between nodes representing respective attack paths between respective nodes (Paragraph [0525] of Kumar discloses the security graph may include a plurality of nodes representing entities of a compute environment and a plurality of edges interconnecting the nodes to represent relationships between the entities);
determining a first level of structural similarity between a first node and a second node of the nodes satisfies a structural similarity criterion; subsequent to determining the first level of structural similarity satisfies the structural similarity criterion, grouping the first node and the second node together in a grouped node, resulting in a modified graph (Paragraph [0167] of Kumar discloses a total of three different etcdct1 processes were executed during the 9 am-10 am window, and were clustered together (260). FIG. 2H also depicts two different clusters that are both named etcd2. The first cluster includes (for the 9 am-10 am window) five members (261) and the second cluster includes (for the same window) eight members (262). The reason for these two distinct clusters is that the two groups of applications behave differently (e.g., they exhibit two distinct sets of communication patterns). Specifically, the instances of etcd2 in cluster 261 only communicate with locksmithct1 (263) and other etcd2 instances (in both clusters 261 and 262). The instances of etcd2 in cluster 262 communicate with additional entities, such as etcdct1 and Docker containers);
identifying a security vulnerability of the network-based computing system based on the modified graph by:
[identifying a first edge of the edges between the groups node and a third node of the nodes, the third node corresponding to a first key, and
determining the first edge indicates the first key enables access to resources represented by nodes grouped within the grouped node; and mitigating the security vulnerability by dividing at least the first node into a first group of resources accessible by a second key instead of the first key and the second node into a second group of resources accessible by a third key instead of the first key] (Paragraph [0537] of Kumar discloses attack paths may be identified from security graphs 600, prioritized, and provided on a landing page. Thus, the landing page may present top risks across a security posture. Paragraph [0552] of Kumar discloses Where the risk score is determined based on information associated with a security graph 600, the security graph 600 may be used to present evidence of reasons for a determined risk score, which may help a user understand the reasons for a risk score and how to address the risk factors that made up the risk score. This helps users readily determine how to prioritize their workflows to mitigate risk effectively).
Kumar does not explicitly disclose an edge being an attack path. However, such a feature would have been obvious in view of Kumar. Paragraph [0543] of Kumar discloses the security graph 600 may pivot to focus on something associated with the edge, such as a policy or vulnerability associated with the edge. Paragraph [0536] of Kumar discloses attack paths for internet exposed compute instances with critical vulnerabilities. Accordingly, the edges of Kumar have associated vulnerabilities, and the vulnerabilities are representative of attack paths.
Kumar does not explicitly disclose identifying a first edge of the edges between the groups node and a third node of the nodes, the third node corresponding to a first key, and
determining the first edge indicates the first key enables access to resources represented by nodes grouped within the grouped node; and mitigating the security vulnerability by dividing at least the first node into a first group of resources accessible by a second key instead of the first key and the second node into a second group of resources accessible by a third key instead of the first key
However, Rossman discloses this. Column 5 lines 45-55 of Rossman disclose determine alerts on credential cluster vulnerabilities, such as a weakest link credential, over-scoping of permissions, privilege escalation, exploitation of trust relationships, over-scoping of access to the credential clusters, long lived credentials protecting short lived credentials, etc. Column 5 lines 50-60 of Rossman disclose identity ecosystem analyzer 150 can make recommendations regarding scoping of permissions between related credentials, a need for multi-factor authentication, a need for quorum based authorization, a change in credential rotation policy (e.g., more or less time), etc.
Examiner recites the same rationale to combine used for claim 1.
As to Claim 10, Kumar-Rossman discloses the method of claim 9, further comprising: identifying a second edge between the first node and the third node; identifying a third edge between the second node and the third node; and grouping the third and second edges as the first edge (Paragraph [0167] of Kumar discloses a total of three different etcdct1 processes were executed during the 9 am-10 am window, and were clustered together (260). FIG. 2H also depicts two different clusters that are both named etcd2. The first cluster includes (for the 9 am-10 am window) five members (261) and the second cluster includes (for the same window) eight members (262). The reason for these two distinct clusters is that the two groups of applications behave differently (e.g., they exhibit two distinct sets of communication patterns). Specifically, the instances of etcd2 in cluster 261 only communicate with locksmithct1 (263) and other etcd2 instances (in both clusters 261 and 262). The instances of etcd2 in cluster 262 communicate with additional entities, such as etcdct1 and Docker containers).
As to Claim 13, Kumar-Rossman discloses the method of claim 9, wherein said determining the level of structural similarity between the first node and the second node comprises: generating a first sparse vector based on a property and an edge of the first node; generating a second sparse vector based on a property and an edge of the second node; and determining a distance between the first sparse vector and the second sparse vector satisfies the structural similarity criterion (Paragraph [0211] of Kumar discloses clustering, described in more detail below, include performing Matching Neighbor clustering and similarity (e.g., SimRank) clustering).
As to Claim 14, Kumar-Rossman discloses the method of claim 9, further comprising: determining a second level of structural similarity between the first node and a fourth node fails to satisfy the structural similarity criterion; determining a cardinality of the modified graph fails to satisfy a cardinality criterion; adjusting the structural similarity criterion, resulting in a modified structural similarity criterion; determining the second level of structural similarity satisfies the modified structural similarity criterion; grouping the first node, the second node, and the fourth node in the grouped node; and determining the cardinality of the modified graph satisfies the cardinality criterion (Paragraph [0232] of Kumar discloses As a result of performing MNC, SimRank, and cluster splitting (e.g., CmdType splitting) many processes are clustered together based on commonality of behavior (e.g., communication behavior) and commonality of application type. Such clustering represents a significant reduction in graph size (e.g., compared to the original raw physical graph). Nonetheless, further clustering can be performed (e.g., by iterating on the graph data using the GBM to achieve such a polygraph). As more information within the graph is correlated, more nodes can be clustered together, reducing the size of the graph, until convergence is reached and no further clustering is possible).
As to Claim 15, Kumar-Rossman discloses the method of claim 14, wherein the structural similarity criterion specifies a similarity threshold indicative of nodes that share a type and a property and said adjusting the structural similarity criterion comprises: adjusting the similarity threshold to be indicative of nodes that share the type but do not share the property (Paragraph [0214] of Kumar discloses for any two nodes that are members of a given CmdType. Nodes with a threshold amount of commonality. Paragraph [0226] of Kumar discloses SimRank can be modified to use different thresholds.).
As to Claim 16, Kumar-Rossman discloses the method of claim 9, further comprising: causing an indication of the security vulnerability to be presented in a user interface of a computing device, the indication indicating an entry point of the security vulnerability (Paragraph [0537] of Kumar discloses attack paths may be identified from security graphs 600, prioritized, and provided on a landing page. Thus, the landing page may present top risks across a security posture. Paragraph [0552] of Kumar discloses Where the risk score is determined based on information associated with a security graph 600, the security graph 600 may be used to present evidence of reasons for a determined risk score, which may help a user understand the reasons for a risk score and how to address the risk factors that made up the risk score. This helps users readily determine how to prioritize their workflows to mitigate risk effectively).
As to Claim 17, Kumar discloses a computer-readable storage medium encoded with program instructions structured to cause a processor circuit to perform a method comprising:
generating a graph representative of resources in the network-based computing system, the graph comprising nodes representative of the resources and edges between nodes representing respective attack paths between respective nodes (Paragraph [0525] of Kumar discloses the security graph may include a plurality of nodes representing entities of a compute environment and a plurality of edges interconnecting the nodes to represent relationships between the entities);
determining a first level of structural similarity between a first node and a second node of the nodes satisfies a structural similarity criterion; identifying a first edge of the first node having a third node as a point of a first attack path with the first node as a target; identifying a second edge of the second node having the third node as a point of a second attack path with the second nodes as a target; grouping, based on the first level of structural similarity satisfying the structural similarity criterion the first and second edges as a grouped edge, resulting in a modified graph (Paragraph [0167] of Kumar discloses a total of three different etcdct1 processes were executed during the 9 am-10 am window, and were clustered together (260). FIG. 2H also depicts two different clusters that are both named etcd2. The first cluster includes (for the 9 am-10 am window) five members (261) and the second cluster includes (for the same window) eight members (262). The reason for these two distinct clusters is that the two groups of applications behave differently (e.g., they exhibit two distinct sets of communication patterns). Specifically, the instances of etcd2 in cluster 261 only communicate with locksmithct1 (263) and other etcd2 instances (in both clusters 261 and 262). The instances of etcd2 in cluster 262 communicate with additional entities, such as etcdct1 and Docker containers);
identifying a security vulnerability of the network-based computing system based on the modified graph by [determining the grouped edge indicates a first key corresponding to the third nodes enables access to resources represented by nodes coupled to the third node by the grouped edge; and mitigating the security vulnerability by dividing at least the first node into a first group of resources accessible by a second key instead of the first key and the second nodes into the second group of resources accessible by a third key instead of the first key] (Paragraph [0537] of Kumar discloses attack paths may be identified from security graphs 600, prioritized, and provided on a landing page. Thus, the landing page may present top risks across a security posture. Paragraph [0552] of Kumar discloses Where the risk score is determined based on information associated with a security graph 600, the security graph 600 may be used to present evidence of reasons for a determined risk score, which may help a user understand the reasons for a risk score and how to address the risk factors that made up the risk score. This helps users readily determine how to prioritize their workflows to mitigate risk effectively).
Kumar does not explicitly disclose an edge being an attack path. However, such a feature would have been obvious in view of Kumar. Paragraph [0543] of Kumar discloses the security graph 600 may pivot to focus on something associated with the edge, such as a policy or vulnerability associated with the edge. Paragraph [0536] of Kumar discloses attack paths for internet exposed compute instances with critical vulnerabilities. Accordingly, the edges of Kumar have associated vulnerabilities, and the vulnerabilities are representative of attack paths.
Kumar does not explicitly disclose determining the grouped edge indicates a first key corresponding to the third nodes enables access to resources represented by nodes coupled to the third node by the grouped edge; and mitigating the security vulnerability by dividing at least the first node into a first group of resources accessible by a second key instead of the first key and the second nodes into the second group of resources accessible by a third key instead of the first key.
However, Rossman discloses this. Column 5 lines 45-55 of Rossman disclose determine alerts on credential cluster vulnerabilities, such as a weakest link credential, over-scoping of permissions, privilege escalation, exploitation of trust relationships, over-scoping of access to the credential clusters, long lived credentials protecting short lived credentials, etc. Column 5 lines 50-60 of Rossman disclose identity ecosystem analyzer 150 can make recommendations regarding scoping of permissions between related credentials, a need for multi-factor authentication, a need for quorum based authorization, a change in credential rotation policy (e.g., more or less time), etc.
Examiner recites the same rationale to combine used for claim 1.
As to Claim 18, Kumar-Rossman discloses the computer-readable storage medium of claim 17, wherein the method further comprises: determining a level of structural similarity between the first node and the second node; grouping the first and second nodes as a grouped target; wherein said mitigating is performed with respect to the grouped target (Paragraph [0224] of Kumar discloses application of SimRank would cluster nodes p4-p6 into one cluster (314) and also cluster nodes p7-p9 into another cluster (315). Paragraph [0537] of Kumar discloses attack paths may be identified from security graphs 600, prioritized, and provided on a landing page. Thus, the landing page may present top risks across a security posture. Paragraph [0552] of Kumar discloses Where the risk score is determined based on information associated with a security graph 600, the security graph 600 may be used to present evidence of reasons for a determined risk score, which may help a user understand the reasons for a risk score and how to address the risk factors that made up the risk score. This helps users readily determine how to prioritize their workflows to mitigate risk effectively).
As to Claim 19, Kumar-Rossman discloses the computer-readable storage medium of claim 17, wherein said identifying the security vulnerability comprises: determining a number of nodes associated with the grouped edge satisfies a vulnerability criterion (Paragraph [0541] of Kumar discloses nodes may be filtered by resource information such as resource types, resource attributes, etc., by identity information such as user and/or roles, and by risk types such as vulnerabilities, misconfigurations, alerts, and secrets. Paragraph [0551] of Kumar discloses toxic combination may be further defined to include only hosts that are internet exposed and that have access to storage assets. Paragraph [0527] of Kumar discloses visibility into lateral movement, alerts, attack paths, identity risk with access to critical assets, internet exposed hosts that have SSH ports open hosts in production that have active vulnerabilities and active or risked exploit, and blast radius associated with a breach or risk of breach).
As to Claim 20, Kumar-Rossman discloses the computer-readable storage medium of claim 17, wherein the method further comprises: determining a level of structural similarity between the first node and a fourth node fails to satisfy the structural similarity criterion; determining a cardinality of the modified graph fails to satisfy a cardinality criterion; adjusting the structural similarity criterion, resulting in a modified structural similarity criterion; determining the level of structural similarity between the first node and the fourth node satisfies the modified structural similarity criterion; grouping the first node, the second node, and the fourth node in the grouped node; and determining the cardinality of the modified graph satisfies the cardinality criterion (Paragraph [0232] of Kumar discloses As a result of performing MNC, SimRank, and cluster splitting (e.g., CmdType splitting) many processes are clustered together based on commonality of behavior (e.g., communication behavior) and commonality of application type. Such clustering represents a significant reduction in graph size (e.g., compared to the original raw physical graph). Nonetheless, further clustering can be performed (e.g., by iterating on the graph data using the GBM to achieve such a polygraph). As more information within the graph is correlated, more nodes can be clustered together, reducing the size of the graph, until convergence is reached and no further clustering is possible).
As to Claim 21, Kumar-Rossman discloses the security system of claim 1, wherein the graph reducer further: groups the first third node and the first grouped node into a second grouped node representative of keys and resources accessible to a virtual machine; and wherein to identify the security vulnerability, the attack path identifier further: identifies a fourth node representative of the virtual machine and coupled to the second grouped node by a third edge, the third edge indicating the virtual machine has access to resources of the second grouped node (Paragraph [0232] of Kumar discloses As a result of performing MNC, SimRank, and cluster splitting (e.g., CmdType splitting) many processes are clustered together based on commonality of behavior (e.g., communication behavior) and commonality of application type. Such clustering represents a significant reduction in graph size (e.g., compared to the original raw physical graph). Nonetheless, further clustering can be performed (e.g., by iterating on the graph data using the GBM to achieve such a polygraph). As more information within the graph is correlated, more nodes can be clustered together, reducing the size of the graph, until convergence is reached and no further clustering is possible).
As to Claim 22, Kumar-Rossman discloses the method of claim 9, further comprising: grouping the first third node and the first grouped node into a second grouped node representative of keys and resources accessible to a virtual machine; and wherein said identifying the security vulnerability further comprises: identifies a fourth node representative of the virtual machine and coupled to the second grouped node by a second edge indicating the virtual machine has access to resources of the second grouped node (Paragraph [0232] of Kumar discloses As a result of performing MNC, SimRank, and cluster splitting (e.g., CmdType splitting) many processes are clustered together based on commonality of behavior (e.g., communication behavior) and commonality of application type. Such clustering represents a significant reduction in graph size (e.g., compared to the original raw physical graph). Nonetheless, further clustering can be performed (e.g., by iterating on the graph data using the GBM to achieve such a polygraph). As more information within the graph is correlated, more nodes can be clustered together, reducing the size of the graph, until convergence is reached and no further clustering is possible).
As to Claim 23, Kumar-Rossman discloses the method of claim 9, further comprising: generating a linked alert for the first resource and the second resource; detecting anomalous activity with respect to the first resource; and generating, based on the detected anomalous activity, an alert for the second resource (Paragraph [0541] of Kumar discloses nodes may be filtered by resource information such as resource types, resource attributes, etc., by identity information such as user and/or roles, and by risk types such as vulnerabilities, misconfigurations, alerts, and secrets. Paragraph [0551] of Kumar discloses toxic combination may be further defined to include only hosts that are internet exposed and that have access to storage assets. Paragraph [0527] of Kumar discloses visibility into lateral movement, alerts, attack paths, identity risk with access to critical assets, internet exposed hosts that have SSH ports open hosts in production that have active vulnerabilities and active or risked exploit, and blast radius associated with a breach or risk of breach).
As to Claim 24, Kumar-Rossman discloses the computer-readable storage medium of claim 17, wherein the method further comprises: grouping the first third node and the first grouped node into a second grouped node representative of keys and resources accessible to a virtual machine; and wherein said identifying the security vulnerability further comprises: identifies a fourth node representative of the virtual machine and coupled to the second grouped node by a second edge indicating the virtual machine has access to resources of the second grouped node (Paragraph [0232] of Kumar discloses As a result of performing MNC, SimRank, and cluster splitting (e.g., CmdType splitting) many processes are clustered together based on commonality of behavior (e.g., communication behavior) and commonality of application type. Such clustering represents a significant reduction in graph size (e.g., compared to the original raw physical graph). Nonetheless, further clustering can be performed (e.g., by iterating on the graph data using the GBM to achieve such a polygraph). As more information within the graph is correlated, more nodes can be clustered together, reducing the size of the graph, until convergence is reached and no further clustering is possible).
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Kevin S Mai whose telephone number is (571)270-5001. The examiner can normally be reached Monday to Friday 9AM to 5PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Philip Chea can be reached at 5712723951. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/KEVIN S MAI/Primary Examiner, Art Unit 2499