DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
This written action is responding to the amendment dated on 08/07/2026.
Claims 1-13 are previously presented.
Claims 1-13 are pending.
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
Examiner’s Note
Applicant has claimed priority from various provisional applications, continuing parent applications and continuing in part parent applications. Examiner has reviewed the support for claimed invention and found the support only in parent application 18/436,045. Hence the priority will be considered as of parent application 18/436,045 filed on August 02, 2024 for an examination purpose.
Information Disclosure Statement
The following Information Disclosure Statements in the instant application submitted in compliance with the provisions of 37 CFR 1.97, and thus, have been fully considered:
IDS filed on 13 October 2024.
Response to Arguments
Applicant’s amendment, filed on August 07, 2026 has claims 1-13 previously presented.
The prior double patenting rejection of Claims 1, 3-7 and 9-13 has been withdrawn in view of the filed and approved electronic terminal disclaimer on August 07, 2026.
Applicant’s remark, filed on August 07, 2026 on pages 6-10 regarding 35 U.S.C. 101 abstract idea rejection has been considered, however is not found persuasive.
Applicant has provided various sections of MPEP to evaluate the claims for 35 U.S.C. 101 as an abstract idea. Examiner has interpreted the claims as per guidance of the MPEP and identified the claims under the grouping of “Mental Process”. The courts consider a mental process (thinking) that "can be performed in the human mind, or by a human using a pen and paper" to be an abstract idea. CyberSource Corp. v. Retail Decisions, Inc., 654 F.3d 1366, 1372, 99 USPQ2d 1690, 1695 (Fed. Cir. 2011). As the Federal Circuit explained, "methods which can be performed mentally, or which are the equivalent of human mental work, are unpatentable abstract ideas the ‘basic tools of scientific and technological work’ that are open to all.’" 654 F.3d at 1371, 99 USPQ2d at 1694 (citing Gottschalk v. Benson, 409 U.S. 63, 175 USPQ 673 (1972)). See also Mayo Collaborative Servs. v. Prometheus Labs. Inc., 566 U.S. 66, 71, 101 USPQ2d 1961, 1965 (2012) ("‘[M]ental processes[] and abstract intellectual concepts are not patentable, as they are the basic tools of scientific and technological work’" (quoting Benson, 409 U.S. at 67, 175 USPQ at 675)); Parker v. Flook, 437 U.S. 584, 589, 198 USPQ 193, 197 (1978) (same).
Accordingly, the "mental processes" abstract idea grouping is defined as concepts performed in the human mind, and examples of mental processes include observations, evaluations, judgments, and opinions. A discussion of concepts performed in the human mind, as well as concepts that cannot practically be performed in the human mind and thus are not "mental processes", is provided below.
The courts do not distinguish between mental processes that are performed entirely in the human mind and mental processes that require a human to use a physical aid (e.g., pen and paper or a slide rule) to perform the claim limitation. See, e.g., Benson, 409 U.S. at 67, 65, 175 USPQ at 674-75, 674 (noting that the claimed "conversion of [binary-coded decimal] numerals to pure binary numerals can be done mentally," i.e., "as a person would do it by head and hand."); Synopsys, Inc. v. Mentor Graphics Corp., 839 F.3d 1138, 1139, 120 USPQ2d 1473, 1474 (Fed. Cir. 2016) (holding that claims to a mental process of "translating a functional description of a logic circuit into a hardware component description of the logic circuit" are directed to an abstract idea, because the claims "read on an individual performing the claimed steps mentally or with pencil and paper"). Mental processes performed by humans with the assistance of physical aids such as pens or paper are explained further below.
Nor do the courts distinguish between claims that recite mental processes performed by humans and claims that recite mental processes performed on a computer. As the Federal Circuit has explained, "[c]ourts have examined claims that required the use of a computer and still found that the underlying, patent-ineligible invention could be performed via pen and paper or in a person’s mind." Versata Dev. Group v. SAP Am., Inc., 793 F.3d 1306, 1335, 115 USPQ2d 1681, 1702 (Fed. Cir. 2015). See also Intellectual Ventures I LLC v. Symantec Corp., 838 F.3d 1307, 1318, 120 USPQ2d 1353, 1360 (Fed. Cir. 2016) (‘‘[W]ith the exception of generic computer-implemented steps, there is nothing in the claims themselves that foreclose them from being performed by a human, mentally or with pen and paper.’’); Mortgage Grader, Inc. v. First Choice Loan Servs. Inc., 811 F.3d 1314, 1324, 117 USPQ2d 1693, 1699 (Fed. Cir. 2016) (holding that computer-implemented method for "anonymous loan shopping" was an abstract idea because it could be "performed by humans without a computer"). MPEP 2106.04(a)(2) III. Applicant’s further argues on bottom of page 6 and top of page 7 regarding, “The Examiner reaches the mental-process conclusion only by disregarding express claim language and replacing the claimed operation with a materially different hypothetical. Claim 1 does not merely recite receiving generic "data" and comparing it against a "table." It recites receiving "data related to an observed event, the data comprising at least one computed statistical measure of a data stream," and comparing the received data against "a database comprising a plurality of signatures." The claim therefore requires receipt of a statistical measure that has been computed over a data stream and evaluation of that received data against a signature database as part of an automated monitoring operation. The proper inquiry is whether the limitations, as claimed, can practically be performed in the human mind. It is not proper to remove the claimed computing environment, omit the requirement that the received data comprise a computed statistical measure of a data stream, replace the signature database with a generic table, and then ask whether the resulting hypothetical could be performed mentally. The Examiner's example of a person comparing an observed event against a list of events is not the claimed operation. The claimed receipt and comparison of a computed statistical measure of a data stream against a database of signatures are not operations that can practically be performed in the human mind in the manner recited. They are computer-implemented operations performed on data generated through computational analysis of a data stream. The Examiner's analogy is reached only by excising the "computed statistical measure of a data stream" limitation and materially altering the nature of the claimed comparison”, has been considered however is not found persuasive, the claim only recites receiving data related to an observed event. The data comprising at least one computed statistical measure of a data stream, compare the received data to a database comprising a plurality of signatures, when comparison yields a match generate an alert comprising the received data and send the alert to a monitoring system, along with generic computer components. As explained above on pages 4-5 these steps can be performed by a human, who receives data related to an observed event and compares against a list (database) and determines an issue when a matching is found and communicate an alert to an authority. Applicant’s further remark, on bottom of page 9 regarding, “Claim 1 recites significantly more than any alleged judicial exception. The claimed ordered combination of receiving data comprising a computed statistical measure of a data stream, comparing the received data against a signature database, and conditionally generating and routing an alert to a monitoring system is not established as a well- understood, routine, and conventional arrangement”, has been considered, however is not found persuasive. Contrary to the Applicant’s belief, comparing data and generating a notification is well- understood, routine, and conventional arrangement steps.
Applicant’s remark, filed on August 07, 2026 on top of page 11 regarding, “Deardorff does not teach that the received event data compared against its signatures comprises a computed statistical measure of a data stream. Vasilenko does not remedy this deficiency” has been considered, however is not found persuasive. Vasilenko discloses, “The intrusion detection system 110 is configured to process the sequence of data packets as they enter the network to determine whether the data object 102 is malicious. In particular, the intrusion detection system 110 can reconstruct the sequence of data packets to generate a sequence of stream objects representing the data object 102. That is, each stream object can be generated from a subsequence of the data packets. In this specification, a stream object is any sequence of bytes representing some or all of a data object that is generated by reassembling data packets of the data object. The intrusion detection system can then iteratively analyze a sliding window of one or more of the stream objects of the data object 102 to determine whether the data object 102 is malicious. (Fig. 1, ¶25). “The data object 102 can include multiple different components, where each component is represented by a respective different subsequence of the sequence of data packets of the data object. Each component can then be represented in a sequence of one or more reconstructed stream objects. In some implementations, each component is only included in a single stream object of the data object 102; that is, the representation of a single component cannot be spread across multiple different stream objects”. (¶29). “The component tracking system 150 is configured to maintain data tracking, for each component 142 of each data object 102 analyzed by the code reuse analysis system 130: (i) how often the component 142 has been identified in a data object 102 classified as malicious and (ii) how often the component 142 has been identified in a data object 102 classified as benign. In implementations in which the malware detection system 140 also classifies data objects 102 as inconclusive, the component tracking system 150 can also maintain data tracking, for each component 142 of each data object 102 analyzed by the code reuse analysis system: (iii) how often the component 142 has been identified in a data object 102 classified as inconclusive. Different malicious data objects 102 often include the same components 142. By tracking the historical frequencies with which components 142 are observed in malicious and benign data objects 102, the code reuse analysis system 130 can identify the components 142 that, when observed in a new data object 102, indicate that the data object 102 is likely to be malicious. The code reuse analysis system 130 can then generate new IDS rules 132 using the identified components”. (¶59-¶60). “FIG. 2 is an illustration of an example component tracking table 200. The component tracking table 200 can be maintained by a component tracking system of a code reuse analysis system, e.g., the component tracking system 150 of the code reuse analysis system 130 depicted in FIG. 1. Each row of the component tracking table 200 corresponds to a respective different component of a respective data object observed by a code reuse analysis system. Each component can be identified in any appropriate way. For example, as illustrated in FIG. 2, each component can be identified by a hash value generated by processing the component using a hash function, e.g., a Message Digest (MD) hash function or a Secure Hashing Algorithm (SHA) hash function. As described above, in some implementations before processing a component using the hash function, the code reuse analysis system can remove unstable portions of the component, e.g., by processing the component using a binary mask. The row of the component tracking table 200 corresponding to each component identifies (i) a number of times the component has been observed in data objects determined to be malicious, (ii) a number of times the component has been observed in data objects determined to be benign, and (iii) a number of times the component has been observed in data objects determined to be inconclusive”. (Fig. 2, ¶63-¶65). “Although the component tracking table 200 of FIG. 2 maintains data tracking raw counts of occurrences for each observed component, generally a component tracking table can maintain any appropriate data that characterizes a frequency with which each component has been observed in respective types of data objects. For example, a component tracking table can maintain data identifying, for each component, (i) a proportion of malicious data objects the component has been observed in (e.g., 5% of all malicious data objects observed by the code reuse analysis system), (ii) a proportion of benign data objects the component has been observed in, and (iii) a proportion of inconclusive data objects the component has been observed in”. (¶69). Deardorff teaches, “For example, FIG. 4 illustrates exemplary “fingerprint” data 402 regarding virtual device 302a of FIG. 3. This fingerprint data 402 may include, but is not limited to, products executing on the device 302a, product version, vendors, etc. The fingerprint data 402 may also include security-related data, such as who has access to the device 302a and their authorizations. As another example, FIG. 5 illustrates exemplary fingerprint data 502 for a file in the storage 306 of FIG. 3. For a given stored file, the fingerprint data 502 may include attributes such as file size, creation or last saved date, type, creator, users with read access permissions, users with write access permissions, etc. As seen in FIG. 5, the fingerprint data 502 for this particular file includes an MD5 hash. The above data is merely exemplary, and other types of data regarding files, processes, devices, security permissions, or any other type of data regarding network activity and/or configurations may be considered in conjunction with the systems and methods described herein. Once the computing environment is configured, the attack module 116 may execute one or more attack tools to simulate malicious activity. It is noted that the terms “simulate malicious activity” or “simulated malicious activity” refers to activity that occurs in the computing environment and that, if occurring in an actual target network, would constitute malicious activity. In other words, the malicious activity that is “simulated” refers to activity that occurs in the generated computing environment. (Fig. 4, Fig. 5, ¶68-¶70). “Step 1106 involves gathering data regarding a second state of the computing environment after the at least one attack tool is executed. This data may include the exemplary data shown in the fingerprint data of FIG. 4 or 5, for example. The type of data gathered from each device may depend on the type of device. Step 1108 involves detecting at least one trace of the malicious activity from the data regarding the second state of the computing environment. As discussed previously, attack tools leave behind traces that may at least suggest malicious activity has taken place. These traces may relate to changes in file size, file save date, read access permissions, write access permissions, hashes, or any other type of data that may indicate that malicious activity has occurred in a computing environment”. (Fig. 11(1104, 1106), ¶111-¶112). Thus a person having an ordinary skill in the art would have combined the Vasilenko who teaches receiving observed data that comprises statistical measure of a data stream in particular historical frequency associated with components of data objects with receiving observed data of an event such as changes in file size, file save data, read access permissions, write access permissions, hashes and compares against stored signature of Deardorff. The motivation/suggestion for doing so would be to identify malicious data objects that include the one or more particular tracked components in the past history.
The Applicant’s remark, filed on August 07, 2026 on middle of page 13 regarding, “The rejection states that it would have been obvious to combine Vasilenko's receipt of data comprising a statistical measure with Deardorff's generation of an alert based on comparison to a signature database "to identify malicious data objects that include the one or more particular tracked components in the past history." That rationale describes Vasilenko's existing arrangement: historical observations of components are used to generate signatures, and data objects are subsequently matched against those signatures. It does not provide a reason to modify Deardorff so that the event data compared against its signature database comprises a computed statistical measure of a data stream. An obviousness conclusion must be supported by a rational underpinning connecting the cited teachings to the claimed invention, and the rationale of combining known elements to yield predictable results requires that the proposed combination actually yield the claimed arrangement. See MPEP § 2143; KSR Int'l Co. v. Teleflex Inc., 550 U.S. 398 (2007). Here, the stated combination preserves Vasilenko's use of historical frequency for signature generation rather than placing that measure within the received event data compared against signatures. The rejection therefore does not explain how the proposed combination yields the limitations of Claim 1. The rejection also identifies no teaching or reason that would have led a skilled artisan to alter the role of Vasilenko's historical frequency (from information used to determine whether to generate a signature) to a component of the received event data compared against a signature database. Supplying that unarticulated modification only after reviewing Claim 1 would constitute impermissible hindsight. See MPEP §2142 has been considered. In response to applicant's argument that the examiner's conclusion of obviousness is based upon improper hindsight reasoning, it must be recognized that any judgment on obviousness is in a sense necessarily a reconstruction based upon hindsight reasoning. But so long as it takes into account only knowledge which was within the level of ordinary skill at the time the claimed invention was made, and does not include knowledge gleaned only from the applicant's disclosure, such a reconstruction is proper. See In re McLaughlin, 443 F.2d 1392, 170 USPQ 209 (CCPA 1971).
Applicant further recites similar remarks as listed above for dependent claims, 5 and 11. Please see response for remarks in above paragraph 15 that clearly shows how the cited prior arts Deardorff, Vasilenko and Naxi clearly teaches the claimed limitations.
Claim Rejections - 35 USC § 101
35 U.S.C. 101 reads as follows:
Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title.
Claim 1 is rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. The claim recites receive data related to an observed event, the data comprising at least one computed statistical measure of a data stream; compare the received data to a database comprising a plurality of signatures; when the comparison yields a match: generate an alert comprising the received data; and send the alert to a monitoring system.
The limitation of receive data related to an observed event, the data comprising at least one computed statistical measure of a data stream; compare the received data to a database comprising a plurality of signatures, as drafted, is a process that, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components. That is, other than reciting “one or more of the processors,” nothing in the claim element precludes the step from practically being performed in the mind. For example, but for the “one or more of the processors” language, “receive data related to an observe event”, “compare” in the context of this claim encompasses the user compares an observed event with a list of events in a table. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, then it falls within the “Mental Processes” grouping of abstract ideas. Accordingly, the claim recites an abstract idea.
This judicial exception is not integrated into a practical application. In particular, the claim only recites one additional element – when the comparison yields a match: generate an alert comprising the received data; and send the alert to a monitoring system. The one or more processors is recited at a high-level of generality i.e., as a generic processor performing a generic computer function of generating and sending an alert to a monitoring station such that it amounts no more than mere instructions to apply the exception using a generic computer component. Accordingly, this additional element does not integrate the abstract idea into a practical application because it does not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea.
The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception. As discussed above with respect to integration of the abstract idea into a practical application, the additional element of using one or more of the processors to perform generating an alert and sending the alert to a monitoring system amounts to no more than mere instructions to apply the exception using a generic computer component. Mere instructions to apply an exception using a generic computer component cannot provide an inventive concept. The claim is not patent eligible.
The other independent Claims, Claim 7 and Claim 13 recites similar limitations and therefore they are also rejected under 35 U.S.C. 101.
Dependent claims 2-6 and 8-12 do not represent significantly more and are too directed to non-statutory subject matter.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-4, 6-10 and 12-13 are rejected under 35 U.S.C. 103 as being unpatentable over Deardorff et al. (US PGPUB. # US 2021/0352092, hereinafter “Deardorff”), and further in view of Vasilenko et al. (US PGPUB. # US 2023/0022279, hereinafter “Vasilenko”).
Referring to Claims 1, 7 and 13:
Regarding Claim 1, Deardorff teaches,
A system for data compression with intrusion detection, comprising:
a plurality of computing devices each comprising at least a processor, a memory, and a network interface; (Fig. 1, ¶56, ¶59-¶60) and
a plurality of programming instructions that, when operating on one or more of the processors, causes the plurality of computing devices to: (Fig. 1, ¶56)
receive data related to an observed event, (Fig. 4, Fig. 5, ¶68-¶70, Fig. 11(1104, 1106), ¶111, ¶112, “These traces may relate to changes in file size, file save date, read access permissions, write access permissions, hashes, or any other type of data that may indicate that malicious activity has occurred in a computing environment”, i.e. data related to an observed event is received) [the data comprising at least one computed statistical measure of a data stream];
compare the received data to a database comprising a plurality of signatures; (¶87, “The generated signature(s) may be stored in one or more databases 130 and be used to at least assist in monitoring activity occurring in a target network”, Fig. 11(1112), ¶114, “to detect activity matching the at least one generated signature, wherein activity matching the at least one generated signature indicates malicious activity”, “Upon detecting activity on the target network matching the generated signature(s), it can be inferred that malicious activity has occurred on the target network”, i.e. received data related to an observed event is compared with signature database)
when the comparison yields a match: (Fig. 11(1112), ¶114)
generate an alert comprising the received data; (¶20, “the number of generated alerts regarding detected malicious activity”, ¶84, Fig. 11(1114), ¶115, “Step 1114 involves issuing an alert using a user interface upon detecting activity matching the at least one generated signature”, Claim 29, i.e. in order to communicate the alert an alert is generated) and
send the alert to a monitoring system. (¶11, the method further includes issuing an alert using a user interface upon detecting activity matching the at least one generated signature”, ¶53, “An alert to that effect may be communicated to security personnel”, ¶84, Fig. 11(1114), ¶115, “Step 1114 involves issuing an alert using a user interface upon detecting activity matching the at least one generated signature”).
Deardorff does not teach explicitly,
[receive data related to an observed event], the data comprising at least one computed statistical measure of a data stream.
However, Vasilenko teaches,
[receive data related to an observed event], the data comprising at least one computed statistical measure of a data stream. (Fig. 1, ¶25, “the intrusion detection system 110 can reconstruct the sequence of data packets to generate a sequence of stream objects representing the data object 102”, ¶29, ¶59, ¶60, “By tracking the historical frequencies with which components 142 are observed in malicious and benign data objects 102, the code reuse analysis system 130 can identify the components 142 that, when observed in a new data object 102”, Fig. 2, ¶63-¶65, ¶69, “a component tracking table can maintain any appropriate data that characterizes a frequency with which each component has been observed in respective types of data objects”, i.e. Deardorff teaches, receiving data related to an observed event such as changes in file size, file save date, read access permissions, write access permissions, hashes, Vasilenko teaches, receiving data comprising a statistical measure of a data steam. Examiner interprets historical frequency associated with components of data objects as a statistical measure of a data stream).
As per KSR vs Teleflex, combining prior art elements according to known methods (device, product) to yield predictable results may be used to create a prima facie case of obviousness.
It would have been obvious to one of ordinary skill in the art before the effective filing date to have combined the teachings of Vasilenko with the invention of Deardorff.
Deardorff teaches, generating an alert by comparing received data to a signature database. Vasilenko teaches, receiving data comprising statistical measure of a data stream. Therefore, it would have been obvious to receive data comprising statistical measure of a data stream of Vasilenko with generating an alert by comparing received data to a signature database of Deardorff to identify malicious data objects that include the one or more particular tracked components in the past history.
KSR Int’l v. Teleflex Inc., 127 S. Ct. 1727, 1740-41, 82 USPQ2d 1385, 1396 (2007).
Regarding Claim 7, it is a method Claim of above System Claim 1 and therefore Claim 7 is rejected with the same rationale as applied against Claim 1 above.
Regarding Claim 13, it is a non-transitory computer-readable medium Claim of above System Claim 1 and therefore Claim 13 is rejected with the same rationale as applied against Claim 1 above.
Referring to Claims 2 and 8:
Regarding Claim 2, rejection of Claim 1 is included and for the same motivation Deardorff does not teach explicitly,
The system of claim 1, wherein the plurality of programming instructions further causes the plurality of computing devices to:
receive a data stream;
compute at least one statistical measure of the data stream; and
compare at least one statistical measure to a reference statistical measure.
However, Vasilenko teaches,
The system of claim 1, wherein the plurality of programming instructions further causes the plurality of computing devices to:
receive a data stream; (Fig. 1, ¶25, “the intrusion detection system 110 can reconstruct the sequence of data packets to generate a sequence of stream objects representing the data object 102”, ¶29, i.e. a data stream is received)
compute at least one statistical measure of the data stream; (¶59, ¶60, “By tracking the historical frequencies with which components 142 are observed in malicious and benign data objects 102, the code reuse analysis system 130 can identify the components 142 that, when observed in a new data object 102”, Fig. 2, ¶63-¶65, ¶69, “a component tracking table can maintain any appropriate data that characterizes a frequency with which each component has been observed in respective types of data objects”, Examiner interprets historical frequency associated with components of data objects as a statistical measure of a data stream) and
compare at least one statistical measure to a reference statistical measure. (¶32, “ if the data object 102 matches any of the IDS signatures in the IDS signature library 120, then the intrusion detection system 110 determines the data object to be malicious”, ¶55, ¶80).
Regarding Claim 8, rejection of Claim 7 is included and Claim 8 is rejected with the same rationale as applied against Claim 2 above.
Referring to Claims 3 and 9:
Regarding Claim 3, rejection of Claim 1 is included and for the same motivation Deardorff teaches,
The system of claim 1, wherein the plurality of programming instructions further causes the plurality of computing devices to:
obtain historical event data; (Fig. 4, Fig. 5, ¶68-¶70, Fig. 11(1104, 1106), ¶111, ¶112, “These traces may relate to changes in file size, file save date, read access permissions, write access permissions, hashes, or any other type of data that may indicate that malicious activity has occurred in a computing environment”, i.e. historical malicious event data is received)
generate a signature based on the historical event data and the external intelligence data; (Fig. 11(1110), ¶113, “autonomously generating at least one signature for detecting future malicious activity”, i.e. a signature for known malicious actor is generated) and
store the signature in the database. (¶114, “the signatures generated in step 910 may be stored and later used to monitor activity on an actual, target network”, i.e. signature is stored in a database).
Deardorff does not teach explicitly,
obtain external intelligence data;
However, Vasilenko teaches,
obtain external intelligence data; (Fig. 1 (120), ¶26, “The intrusion detection system 110 includes an IDS signature library 120 that includes one or more IDS signatures”, ¶27, “An IDS signature is typically generated using a data object that is known to be malicious, and defines a pattern exhibited by the malicious data object”, i.e. IDS signature library (database) is considered as data having plurality of known vulnerabilities and malicious actor information).
Regarding Claim 9, rejection of Claim 7 is included and Claim 9 is rejected with the same rationale as applied against Claim 3 above.
Referring to Claims 4 and 10:
Regarding Claim 4, rejection of Claim 3 is included and for the same motivation Deardorff does not teach explicitly,
The system of claim 3, wherein the signature comprises statistical information derived from the historical event data.
However, Vasilenko teaches,
The system of claim 3, wherein the signature comprises statistical information derived from the historical event data. ; (¶59, ¶60, “By tracking the historical frequencies with which components 142 are observed in malicious and benign data objects 102, the code reuse analysis system 130 can identify the components 142 that, when observed in a new data object 102”, Fig. 2, ¶63-¶65, ¶69, “a component tracking table can maintain any appropriate data that characterizes a frequency with which each component has been observed in respective types of data objects”, Examiner interprets historical frequency associated with historical event data).
Regarding Claim 10, rejection of Claim 9 is included and Claim 10 is rejected with the same rationale as applied against Claim 4 above.
Referring to Claims 6 and 12:
Regarding Claim 6, rejection of Claim 3 is included and for the same motivation Deardorff does not teach explicitly,
The system of claim 3, wherein the plurality of programming instructions further causes the plurality of computing devices to:
when the comparison does not yield a match:
generate a signature associated with the received data; and
store the new signature in the database.
However, Vasilenko teaches,
The system of claim 3, wherein the plurality of programming instructions further causes the plurality of computing devices to:
when the comparison does not yield a match: (¶83, “If the code reuse analysis system 130 determines that no such IDS signature is in the library 120 (e.g., if the malicious data object was not identified by the intrusion detection system 110 but was subsequently identified as malicious by another entity of the network, as described above)”, i.e. no match)
generate a signature associated with the received data; ((Fig. 1(160), ¶74, “ the automatic IDS signature generation system 160 can determine to generate a new IDS signature 132 when the number of times that the particular component 142 has been observed in a malicious data object 102 exceeds a predetermined threshold”, ¶75-¶77, ¶83, “then the automatic IDS signature generation system 160 can generate a new IDS signature 132 corresponding to one or more components of the malicious data object, to ensure that future malicious data objects having similar components are identified by the intrusion detection system 110”, i.e. a new IDS signature is generated) and
store the new signature in the database. (Fig. 1, ¶186).
Regarding Claim 12, rejection of Claim 9 is included and Claim 12 is rejected with the same rationale as applied against Claim 6 above.
Claims 5 and 11 are rejected under 35 U.S.C. 103 as being unpatentable over Deardorff et al. (US PGPUB. # US 2021/0352092, hereinafter “Deardorff”), and further in view of Vasilenko et al. (US PGPUB. # US 2023/0022279, hereinafter “Vasilenko”), and further in view of Naxi et al. (CN PGPUB. # CN 11298334, hereinafter “Naxi”).
Referring to Claims 5 and 11:
Regarding Claim 5, rejection of Claim 4 is included and combination of Deardorff and Vasilenko does not teach explicitly,
The system of claim 4, wherein the statistical information comprises at least two different statistical measures.
However, Naxi teaches,
The system of claim 4, wherein the statistical information comprises at least two different statistical measures. (Page - 4, “wherein the acquisition unit is used for acquiring a data set to be detected, and the data set to be detected comprises data samples to be detected, of which a plurality of labels are target labels”, Page-14, “the data set to be detected based on the reference data set and the data set to be detected stored in the database 130, and further inputs the detected data set to be detected into the training device 120 for training. A training model/rule (or algorithm model) 101 is finally generated”, Page 16, Lines (29-49), i.e. statistical information comprises a probability distribution and historical divergence).
As per KSR vs Teleflex, combining prior art elements according to known methods (device, product) to yield predictable results may be used to create a prima facie case of obviousness.
It would have been obvious to one of ordinary skill in the art before the effective filing date to have combined the teachings of Naxi with the invention of Deardorff in view of Vasilenko.
Deardorff in view of Vasilenko teaches, generating an alert by comparing received data to a signature database and receiving data comprising statistical measure of a data stream. Naxi teaches, malicious data comprises probability distribution as well as codeword. Therefore, it would have been obvious to have malicious data comprises probability distribution as well as codeword of Naxi into the teachings of Deardorff in view of Vasilenko to utilize trained data to identify a security risk to the system.
KSR Int’l v. Teleflex Inc., 127 S. Ct. 1727, 1740-41, 82 USPQ2d 1385, 1396 (2007).
Regarding Claim 11, rejection of Claim 10 is included and Claim 11 is rejected with the same rationale as applied against Claim 5 above.
Conclusion
THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Refer to PTO-892, Notice of References Cited for a listing of analogous art.
Fromm (US PGPUB. # US 2023/0246814) discloses, a method includes managing a registry of data intermediaries authorized to receive data from a data provider and of data recipients associated with the data intermediaries. A method includes blocking access in the registry to identities of the data recipients associated with one of the data intermediaries by one or more other of the intermediaries. A method includes providing data to at least one of the data intermediaries and the data recipients based on the registry.
Jain (US PGPUB. # US 2022/0417282) discloses systems provided for facilitating efficient intrusion detection via hierarchical signatures, in accordance with embodiments described herein. In particular, embodiments described herein include obtaining an intrusion signature that includes an intrusion attribute value(s) indicating a malicious attack on a computer network or system. Based on the intrusion signature, a hierarchical signature is generated by including the intrusion attribute value(s) of the intrusion signature in one of a corresponding data structure of hierarchical data structures. Thereafter, a network packet, having a data attribute(s) is obtained. The network packet is determined as suspect of being malicious based on the data attribute(s) of the network packet matching the at intrusion attribute value(s) of the hierarchical signature. The indication of the suspect network packet can be provided, for example for notification of such a suspect network packet.
Menick et al. (US PGPUB. # US 2021/0004677) discloses, computer programs encoded on a computer storage medium, for training an encoder neural network, a decoder neural network, and a prior neural network, and using the trained networks for generative modeling, data compression, and data decompression. In one aspect, a method comprises: providing a given observation as input to the encoder neural network to generate parameters of an encoding probability distribution; determining an updated code for the given observation; selecting a code that is assigned to an additional observation; providing the code assigned to the additional observation as input to the prior neural network to generate parameters of a prior probability distribution; sampling latent variables from the encoding probability distribution; providing the latent variables as input to the decoder neural network to generate parameters of an observation probability distribution; and determining gradients of a loss function.
Maytal (WIPO PUB. # WO 2020/176066) discloses, multi-dimensional visualization of cyber threats to serve as a base for operator guidance as to when, on which system element(s), and which type of action an operator needs to take related to a cyber threat. In some examples, two- or three- dimensional representations of threats based on affected elements, threat type, threat severity, etc. may be generated and periodically updated using light threat detection tools. Threat signatures represented in the visualizations may be compared to historical records and specific threats detected based on comparison. Visualizations may be used for manual threat detection by operators, automatic detection, and/or activation of higher accuracy detection tools.
Kheir et al. (WIPO PUB. # WO 2019/122241) discloses, a preliminary step (101) of acquiring a first dataset comprising a plurality of generic scenarios, a second dataset comprising a plurality of events occurring in the target environment and a third dataset comprising a plurality of alerts. The method further comprises a first step (110) of determining a generic scenario, termed the partial generic scenario, and an alert such that the elementary attack causing this alert corresponds to one or more actions of the partial generic scenario, a second step (120) of determining a plurality of anomalies, each anomaly corresponding to an abnormal event, and a third step (130) of associating, with at least one of the observable variables of the partial generic scenario, the observable value or one of the observable values of one of the determined anomalies.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to DARSHAN I DHRUV whose telephone number is (571)272-4316. The examiner can normally be reached M-F 9:00 AM-5:00 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Yin-Chen Shaw can be reached at 571-272-8878. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/DARSHAN I DHRUV/Primary Examiner, Art Unit 2498