DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This initial written action is responding to the communication dated on 10/13/2024.
Claims 1-13 are submitted for examination.
Claims 1-13 are pending.
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Examiner’s Note
Applicant has claimed priority from various provisional applications, continuing parent applications and continuing in part parent applications. Examiner has reviewed the support for claimed invention and found the support only in parent application 18/436,045. Hence the priority will be consider as of parent application 18/436,045 filed on August 02, 2024 for an examination purpose.
Information Disclosure Statement
The following Information Disclosure Statements in the instant application submitted in compliance with the provisions of 37 CFR 1.97, and thus, have been fully considered:
IDS filed on 13 October 2024.
Double Patenting
The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the conflicting claims are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969).
A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on nonstatutory double patenting provided the reference application or patent either is shown to be commonly owned with the examined application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. See MPEP § 717.02 for applications subject to examination under the first inventor to file provisions of the AIA as explained in MPEP § 2159. See MPEP § 2146 et seq. for applications not subject to examination under the first inventor to file provisions of the AIA . A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b).
The filing of a terminal disclaimer by itself is not a complete reply to a nonstatutory double patenting (NSDP) rejection. A complete reply requires that the terminal disclaimer be accompanied by a reply requesting reconsideration of the prior Office action. Even where the NSDP rejection is provisional the reply must be complete. See MPEP § 804, subsection I.B.1. For a reply to a non-final Office action, see 37 CFR 1.111(a). For a reply to final Office action, see 37 CFR 1.113(c). A request for reconsideration while not provided for in 37 CFR 1.113(c) may be filed after final for consideration. See MPEP §§ 706.07(e) and 714.13.
The USPTO Internet website contains terminal disclaimer forms which may be used. Please visit www.uspto.gov/patent/patents-forms. The actual filing date of the application in which the form is filed determines what form (e.g., PTO/SB/25, PTO/SB/26, PTO/AIA /25, or PTO/AIA /26) should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to www.uspto.gov/patents/apply/applying-online/eterminal-disclaimer.
Claims 1, 3-7 and 9-13 rejected on the ground of nonstatutory double patenting as being unpatentable over claims 1, 3-7 and 9-13 of U.S. Patent No.12,191,889. Although the claims at issue are not identical, they are not patentably distinct from each other. Please refer to comparison table below.
Instant Application 18/914,221
US PAT. # US 12,191,889 (App. # 18/436,045)
DATA COMPRESSION WITH SIGNATURE-BASED INTRUSION DETECTION
DATA COMPRESSION WITH SIGNATURE-BASED INTRUSION DETECTION
1
A system for data compression with intrusion detection, comprising: a plurality of computing devices each comprising at least a processor, a memory, and a network interface; and a plurality of programming instructions that, when operating on one or more of the processors, causes the plurality of computing devices to: receive data related to an observed event, the data comprising at least one computed statistical measure of a data stream; compare the received data to a database comprising a plurality of signatures; when the comparison yields a match: generate an alert comprising the received data; and send the alert to a monitoring system.
1
A system for data compression with intrusion detection, comprising: a plurality of computing devices each comprising at least a processor, a memory, and a network interface; wherein a plurality of programming instructions stored in one or more of the memories and operating on one or more of the processors of the plurality of computing devices causes the plurality of computing devices to: receive anomalous event data, the anomalous event data comprising a computed divergence of a data stream, a computed first probability distribution of the data stream, and one or more codewords; compare the anomalous event data to a database, the database comprising a plurality of signatures, the plurality of signatures comprising statistical information associated with a plurality of known vulnerabilities; when the comparison yields a match: generate an intrusion alert, the intrusion alert comprising the anomalous event data; and send the intrusion alert to a security monitoring system.
3
The system of claim 1, wherein the plurality of programming instructions further causes the plurality of computing devices to: obtain historical event data; obtain external intelligence data; generate a signature based on the historical event data and the external intelligence data; and store the signature in the database.
3
The system of claim 1, wherein the plurality of programming instructions further causes the plurality of computing devices to: obtain a plurality of historical anomalous event data; obtain threat intelligence data, the threat intelligence data comprising at least the plurality of known vulnerabilities and known malicious actor information; generate a signature for a known malicious actor based on the plurality of historical anomalous event data and the plurality of known vulnerabilities; and store the signature in the database.
4
The system of claim 3, wherein the signature comprises statistical information derived from the historical event data.
4
The system of claim 3, wherein the signature comprises statistical information associated with a known vulnerability, the statistical information being derived from the historical anomalous event data.
5
The system of claim 4, wherein the statistical information comprises at least two different statistical measures.
5
The system of claim 4, wherein the statistical information comprises at least a historical divergence and a historical probability distribution.
6
The system of claim 3, wherein the plurality of programming instructions further causes the plurality of computing devices to: when the comparison does not yield a match: generate a signature associated with the received data; and store the new signature in the database.
6
The system of claim 3 wherein the plurality of programming instructions further causes the plurality of computing devices to: when the comparison does not yield a match: generate a signature associated with the received anomalous event data; and store the signature in the database.
7
A method for data compression with intrusion detection, comprising the steps of: receiving data related to an observed event, the data comprising at least one computed statistical measure of a data stream; comparing the received data to a database comprising a plurality of signatures; when the comparison yields a match: generating an alert comprising the received data; and sending the alert to a monitoring system.
7
A method for data compression with intrusion detection, comprising the steps of: receiving anomalous event data, the anomalous event data comprising a computed divergence of a data stream, a computed first probability distribution of the data stream, and one or more codewords; comparing the anomalous event data to a database, the database comprising a plurality of signatures, the plurality of signatures comprising statistical information associated with a plurality of known vulnerabilities; when the comparison yields a match: generating an intrusion alert, the intrusion alert comprising the anomalous event data; and sending the intrusion alert to a security monitoring system.
9
The method of claim 7, further comprising the steps of: obtaining historical event data; obtaining external intelligence data; generating a signature based on the historical event data and the external intelligence data; and storing the signature in the database.
9
The method of claim 7, further comprising the steps of: obtaining a plurality of historical anomalous event data; obtaining threat intelligence data, the threat intelligence data comprising at least the plurality of known vulnerabilities and known malicious actor information; generating a signature for a known malicious actor based on the plurality of historical anomalous event data and the plurality of known vulnerabilities; and storing the signature in the database.
10
The method of claim 9, wherein the signature comprises statistical information derived from the historical event data.
10
The method of claim 9, wherein the signature comprises statistical information associated with a known vulnerability, the statistical information being derived from the historical anomalous event data.
11
The method of claim 10, wherein the statistical information comprises at least two different statistical measures.
11
The method of claim 10, wherein the statistical information comprises at least a historical divergence and a historical probability distribution.
12
The method of claim 9 further comprising the steps of: when the comparison does not yield a match: generating a signature associated with the received data; and storing the new signature in the database.
12
The method of claim 9 further comprising the steps of: when the comparison does not yield a match: generating a signature associated with the received anomalous event data; and storing the signature in the database.
13
A non-transitory computer-readable medium comprising a plurality of programming instructions that, when operating on a plurality of computing devices each comprising at least a processor, a memory, and a network interface, cause the plurality of computing devices to: receive data related to an observed event, the data comprising at least one computed statistical measure of a data stream; compare the received data to a database comprising a plurality of signatures; when the comparison yields a match: generate an alert comprising the received data; and send the alert to a monitoring system.
13
A non-transitory computer-readable medium comprising a plurality of programming instructions that, when operating on a plurality of computing devices each comprising at least a processor, a memory, and a network interface, cause the plurality of computing devices to: receive anomalous event data, the anomalous event data comprising a computed divergence of a data stream, a computed first probability distribution of the data stream, and one or more codewords; compare the anomalous event data to a database, the database comprising a plurality of signatures, the plurality of signatures comprising statistical information associated with a plurality of known vulnerabilities; and when the comparison yields a match: generate an intrusion alert, the intrusion alert comprising the anomalous event data; and send the intrusion alert to a security monitoring system.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claim 1 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The claim recites receive data related to an observed event, the data comprising at least one computed statistical measure of a data stream; compare the received data to a database comprising a plurality of signatures; when the comparison yields a match: generate an alert comprising the received data; and send the alert to a monitoring system.
The limitation of receive data related to an observed event, the data comprising at least one computed statistical measure of a data stream; compare the received data to a database comprising a plurality of signatures, as drafted, is a process that, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components. That is, other than reciting “one or more of the processors,” nothing in the claim element precludes the step from practically being performed in the mind. For example, but for the “one or more of the processors” language, “receive data related to an observe event”, “compare” in the context of this claim encompasses the user compares an observed event with a list of events in a table. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, then it falls within the “Mental Processes” grouping of abstract ideas. Accordingly, the claim recites an abstract idea.
This judicial exception is not integrated into a practical application. In particular, the claim only recites one additional element – when the comparison yields a match: generate an alert comprising the received data; and send the alert to a monitoring system. The one or more processors is recited at a high-level of generality i.e., as a generic processor performing a generic computer function of generating and sending an alert to a monitoring station such that it amounts no more than mere instructions to apply the exception using a generic computer component. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea.
The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element of using one or more of the processors to perform generating an alert and sending the alert to a monitoring system amounts to no more than mere instructions to apply the exception using a generic computer component. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. The claim is not patent eligible.
The other independent Claims, Claim 7 and Claim 13 recites similar limitations and therefore they are also rejected under 35 U.S.C. 101.
Dependent claims 2-6 and 8-12 do not represent significantly more and are too directed to non-statutory subject matter.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-4, 6-10 and 12-13 are rejected under 35 U.S.C. 103 as being unpatentable over Deardorff et al. (US PGPUB. # US 2021/0352092, hereinafter “Deardorff”), and further in view of Vasilenko et al. (US PGPUB. # US 2023/0022279, hereinafter “Vasilenko”).
Referring to Claims 1, 7 and 13:
Regarding Claim 1, Deardorff teaches,
A system for data compression with intrusion detection, comprising:
a plurality of computing devices each comprising at least a processor, a memory, and a network interface; (Fig. 1, ¶56, ¶59-¶60) and
a plurality of programming instructions that, when operating on one or more of the processors, causes the plurality of computing devices to: (Fig. 1, ¶56)
receive data related to an observed event, (Fig. 4, Fig. 5, ¶68-¶70, Fig. 11(1104, 1106), ¶111, ¶112, “These traces may relate to changes in file size, file save date, read access permissions, write access permissions, hashes, or any other type of data that may indicate that malicious activity has occurred in a computing environment”, i.e. data related to an observed event is received) [the data comprising at least one computed statistical measure of a data stream];
compare the received data to a database comprising a plurality of signatures; (¶87, “The generated signature(s) may be stored in one or more databases 130 and be used to at least assist in monitoring activity occurring in a target network”, Fig. 11(1112), ¶114, “to detect activity matching the at least one generated signature, wherein activity matching the at least one generated signature indicates malicious activity”, “Upon detecting activity on the target network matching the generated signature(s), it can be inferred that malicious activity has occurred on the target network”, i.e. received data related to an observed event is compared with signature database)
when the comparison yields a match: (Fig. 11(1112), ¶114)
generate an alert comprising the received data; (¶20, “the number of generated alerts regarding detected malicious activity”, ¶84, Fig. 11(1114), ¶115, “Step 1114 involves issuing an alert using a user interface upon detecting activity matching the at least one generated signature”, Claim 29, i.e. in order to communicate the alert an alert is generated) and
send the alert to a monitoring system. (¶11, the method further includes issuing an alert using a user interface upon detecting activity matching the at least one generated signature”, ¶53, “An alert to that effect may be communicated to security personnel”, ¶84, Fig. 11(1114), ¶115, “Step 1114 involves issuing an alert using a user interface upon detecting activity matching the at least one generated signature”).
Deardorff does not teach explicitly,
[receive data related to an observed event], the data comprising at least one computed statistical measure of a data stream.
However, Vasilenko teaches,
[receive data related to an observed event], the data comprising at least one computed statistical measure of a data stream. (Fig. 1, ¶25, “the intrusion detection system 110 can reconstruct the sequence of data packets to generate a sequence of stream objects representing the data object 102”, ¶29, ¶59, ¶60, “By tracking the historical frequencies with which components 142 are observed in malicious and benign data objects 102, the code reuse analysis system 130 can identify the components 142 that, when observed in a new data object 102”, Fig. 2, ¶63-¶65, ¶69, “a component tracking table can maintain any appropriate data that characterizes a frequency with which each component has been observed in respective types of data objects”, i.e. Deardorff teaches, receiving data related to an observed event such as changes in file size, file save date, read access permissions, write access permissions, hashes, Vasilenko teaches, receiving data comprising a statistical measure of a data steam. Examiner interprets historical frequency associated with components of data objects as a statistical measure of a data stream).
As per KSR vs Teleflex, combining prior art elements according to known methods (device, product) to yield predictable results may be used to create a prima facie case of obviousness.
It would have been obvious to one of ordinary skill in the art before the effective filing date to have combined the teachings of Vasilenko with the invention of Deardorff.
Deardorff teaches, generating an alert by comparing received data to a signature database. Vasilenko teaches, receiving data comprising statistical measure of a data stream. Therefore, it would have been obvious to receive data comprising statistical measure of a data stream of Vasilenko with generating an alert by comparing received data to a signature database of Deardorff to identify malicious data objects that include the one or more particular tracked components in the past history.
KSR Int’l v. Teleflex Inc., 127 S. Ct. 1727, 1740-41, 82 USPQ2d 1385, 1396 (2007).
Regarding Claim 7, it is a method Claim of above System Claim 1 and therefore Claim 7 is rejected with the same rationale as applied against Claim 1 above.
Regarding Claim 13, it is a non-transitory computer-readable medium Claim of above System Claim 1 and therefore Claim 13 is rejected with the same rationale as applied against Claim 1 above.
Referring to Claims 2 and 8:
Regarding Claim 2, rejection of Claim 1 is included and for the same motivation Deardorff does not teach explicitly,
The system of claim 1, wherein the plurality of programming instructions further causes the plurality of computing devices to:
receive a data stream;
compute at least one statistical measure of the data stream; and
compare at least one statistical measure to a reference statistical measure.
However, Vasilenko teaches,
The system of claim 1, wherein the plurality of programming instructions further causes the plurality of computing devices to:
receive a data stream; (Fig. 1, ¶25, “the intrusion detection system 110 can reconstruct the sequence of data packets to generate a sequence of stream objects representing the data object 102”, ¶29, i.e. a data stream is received)
compute at least one statistical measure of the data stream; (¶59, ¶60, “By tracking the historical frequencies with which components 142 are observed in malicious and benign data objects 102, the code reuse analysis system 130 can identify the components 142 that, when observed in a new data object 102”, Fig. 2, ¶63-¶65, ¶69, “a component tracking table can maintain any appropriate data that characterizes a frequency with which each component has been observed in respective types of data objects”, Examiner interprets historical frequency associated with components of data objects as a statistical measure of a data stream) and
compare at least one statistical measure to a reference statistical measure. (¶32, “ if the data object 102 matches any of the IDS signatures in the IDS signature library 120, then the intrusion detection system 110 determines the data object to be malicious”, ¶55, ¶80).
Regarding Claim 8, rejection of Claim 7 is included and Claim 8 is rejected with the same rationale as applied against Claim 2 above.
Referring to Claims 3 and 9:
Regarding Claim 3, rejection of Claim 1 is included and for the same motivation Deardorff teaches,
The system of claim 1, wherein the plurality of programming instructions further causes the plurality of computing devices to:
obtain historical event data; (Fig. 4, Fig. 5, ¶68-¶70, Fig. 11(1104, 1106), ¶111, ¶112, “These traces may relate to changes in file size, file save date, read access permissions, write access permissions, hashes, or any other type of data that may indicate that malicious activity has occurred in a computing environment”, i.e. historical malicious event data is received)
generate a signature based on the historical event data and the external intelligence data; (Fig. 11(1110), ¶113, “autonomously generating at least one signature for detecting future malicious activity”, i.e. a signature for known malicious actor is generated) and
store the signature in the database. (¶114, “the signatures generated in step 910 may be stored and later used to monitor activity on an actual, target network”, i.e. signature is stored in a database).
Deardorff does not teach explicitly,
obtain external intelligence data;
However, Vasilenko teaches,
obtain external intelligence data; (Fig. 1 (120), ¶26, “The intrusion detection system 110 includes an IDS signature library 120 that includes one or more IDS signatures”, ¶27, “An IDS signature is typically generated using a data object that is known to be malicious, and defines a pattern exhibited by the malicious data object”, i.e. IDS signature library (database) is considered as data having plurality of known vulnerabilities and malicious actor information).
Regarding Claim 9, rejection of Claim 7 is included and Claim 9 is rejected with the same rationale as applied against Claim 3 above.
Referring to Claims 4 and 10:
Regarding Claim 4, rejection of Claim 3 is included and for the same motivation Deardorff does not teach explicitly,
The system of claim 3, wherein the signature comprises statistical information derived from the historical event data.
However, Vasilenko teaches,
The system of claim 3, wherein the signature comprises statistical information derived from the historical event data. ; (¶59, ¶60, “By tracking the historical frequencies with which components 142 are observed in malicious and benign data objects 102, the code reuse analysis system 130 can identify the components 142 that, when observed in a new data object 102”, Fig. 2, ¶63-¶65, ¶69, “a component tracking table can maintain any appropriate data that characterizes a frequency with which each component has been observed in respective types of data objects”, Examiner interprets historical frequency associated with historical event data).
Regarding Claim 10, rejection of Claim 9 is included and Claim 10 is rejected with the same rationale as applied against Claim 4 above.
Referring to Claims 6 and 12:
Regarding Claim 6, rejection of Claim 3 is included and for the same motivation Deardorff does not teach explicitly,
The system of claim 3, wherein the plurality of programming instructions further causes the plurality of computing devices to:
when the comparison does not yield a match:
generate a signature associated with the received data; and
store the new signature in the database.
However, Vasilenko teaches,
The system of claim 3, wherein the plurality of programming instructions further causes the plurality of computing devices to:
when the comparison does not yield a match: (¶83, “If the code reuse analysis system 130 determines that no such IDS signature is in the library 120 (e.g., if the malicious data object was not identified by the intrusion detection system 110 but was subsequently identified as malicious by another entity of the network, as described above)”, i.e. no match)
generate a signature associated with the received data; ((Fig. 1(160), ¶74, “ the automatic IDS signature generation system 160 can determine to generate a new IDS signature 132 when the number of times that the particular component 142 has been observed in a malicious data object 102 exceeds a predetermined threshold”, ¶75-¶77, ¶83, “then the automatic IDS signature generation system 160 can generate a new IDS signature 132 corresponding to one or more components of the malicious data object, to ensure that future malicious data objects having similar components are identified by the intrusion detection system 110”, i.e. a new IDS signature is generated) and
store the new signature in the database. (Fig. 1, ¶186).
Regarding Claim 12, rejection of Claim 9 is included and Claim 12 is rejected with the same rationale as applied against Claim 6 above.
Claims 5 and 11 are rejected under 35 U.S.C. 103 as being unpatentable over Deardorff et al. (US PGPUB. # US 2021/0352092, hereinafter “Deardorff”), and further in view of Vasilenko et al. (US PGPUB. # US 2023/0022279, hereinafter “Vasilenko”), and further in view of Naxi et al. (CN PGPUB. # CN 11298334, hereinafter “Naxi”).
Referring to Claims 5 and 11:
Regarding Claim 5, rejection of Claim 4 is included and combination of Deardorff and Vasilenko does not teach explicitly,
The system of claim 4, wherein the statistical information comprises at least two different statistical measures.
However, Naxi teaches,
The system of claim 4, wherein the statistical information comprises at least two different statistical measures. (Page - 4, “wherein the acquisition unit is used for acquiring a data set to be detected, and the data set to be detected comprises data samples to be detected, of which a plurality of labels are target labels”, Page-14, “the data set to be detected based on the reference data set and the data set to be detected stored in the database 130, and further inputs the detected data set to be detected into the training device 120 for training. A training model/rule (or algorithm model) 101 is finally generated”, Page 16, Lines (29-49), i.e. statistical information comprises a probability distribution and historical divergence).
As per KSR vs Teleflex, combining prior art elements according to known methods (device, product) to yield predictable results may be used to create a prima facie case of obviousness.
It would have been obvious to one of ordinary skill in the art before the effective filing date to have combined the teachings of Naxi with the invention of Deardorff in view of Vasilenko.
Deardorff in view of Vasilenko teaches, generating an alert by comparing received data to a signature database and receiving data comprising statistical measure of a data stream. Naxi teaches, malicious data comprises probability distribution as well as codeword. Therefore, it would have been obvious to have malicious data comprises probability distribution as well as codeword of Naxi into the teachings of Deardorff in view of Vasilenko to utilize trained data to identify a security risk to the system.
KSR Int’l v. Teleflex Inc., 127 S. Ct. 1727, 1740-41, 82 USPQ2d 1385, 1396 (2007).
Regarding Claim 11, rejection of Claim 10 is included and Claim 11 is rejected with the same rationale as applied against Claim 5 above.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Refer to PTO-892, Notice of References Cited for a listing of analogous art.
Fromm (US PGPUB. # US 2023/0246814) discloses, a method includes managing a registry of data intermediaries authorized to receive data from a data provider and of data recipients associated with the data intermediaries. A method includes blocking access in the registry to identities of the data recipients associated with one of the data intermediaries by one or more other of the intermediaries. A method includes providing data to at least one of the data intermediaries and the data recipients based on the registry.
Jain (US PGPUB. # US 2022/0417282) discloses, systems provided for facilitating efficient intrusion detection via hierarchical signatures, in accordance with embodiments described herein. In particular, embodiments described herein include obtaining an intrusion signature that includes an intrusion attribute value(s) indicating a malicious attack on a computer network or system. Based on the intrusion signature, a hierarchical signature is generated by including the intrusion attribute value(s) of the intrusion signature in one of a corresponding data structure of hierarchical data structures. Thereafter, a network packet, having a data attribute(s) is obtained. The network packet is determined as suspect of being malicious based on the data attribute(s) of the network packet matching the at intrusion attribute value(s) of the hierarchical signature. The indication of the suspect network packet can be provided, for example for notification of such a suspect network packet.
Menick et al. (US PGPUB. # US 2021/0004677) discloses, computer programs encoded on a computer storage medium, for training an encoder neural network, a decoder neural network, and a prior neural network, and using the trained networks for generative modeling, data compression, and data decompression. In one aspect, a method comprises: providing a given observation as input to the encoder neural network to generate parameters of an encoding probability distribution; determining an updated code for the given observation; selecting a code that is assigned to an additional observation; providing the code assigned to the additional observation as input to the prior neural network to generate parameters of a prior probability distribution; sampling latent variables from the encoding probability distribution; providing the latent variables as input to the decoder neural network to generate parameters of an observation probability distribution; and determining gradients of a loss function.
Maytal (WIPO PUB. # WO 2020/176066) discloses, multi-dimensional visualization of cyber threats to serve as a base for operator guidance as to when, on which system element(s), and which type of action an operator needs to take related to a cyber threat. In some examples, two- or three- dimensional representations of threats based on affected elements, threat type, threat severity, etc. may be generated and periodically updated using light threat detection tools. Threat signatures represented in the visualizations may be compared to historical records and specific threats detected based on comparison. Visualizations may be used for manual threat detection by operators, automatic detection, and/or activation of higher accuracy detection tools.
Kheir et al. (WIPO PUB. # WO 2019/122241) discloses, a preliminary step (101) of acquiring a first dataset comprising a plurality of generic scenarios, a second dataset comprising a plurality of events occurring in the target environment and a third dataset comprising a plurality of alerts. The method further comprises a first step (110) of determining a generic scenario, termed the partial generic scenario, and an alert such that the elementary attack causing this alert corresponds to one or more actions of the partial generic scenario, a second step (120) of determining a plurality of anomalies, each anomaly corresponding to an abnormal event, and a third step (130) of associating, with at least one of the observable variables of the partial generic scenario, the observable value or one of the observable values of one of the determined anomalies.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to DARSHAN I DHRUV whose telephone number is (571)272-4316. The examiner can normally be reached M-F 9:00 AM-5:00 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Yin-Chen Shaw can be reached at 571-272-8878. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/DARSHAN I DHRUV/Primary Examiner, Art Unit 2498