DETAILED ACTION
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claim(s) 1, 4, 5 and 8 is/are rejected under 35 U.S.C. 103 as being unpatentable over Deardorf et al. (US 2021/0352092) and further in view of Vadlakonda et al. (US 7,953,881).
Consider claim 1, Deardorf et al. in view of Vadlakonda et al. discloses a system for data compression with signature-based verifiable intrusion detection and prediction, comprising one or more computers with executable instructions that, when executed: receive anomalous event data derived from a compressed data stream, the anomalous event data comprising one or more codewords that enable reconstruction of original data by retrieving sourceblocks from a sourceblock library, wherein the one or more codewords comprise a plurality of reference codes to the sourceblocks in the sourceblock library; compare the anomalous event data to a database, the database comprising a plurality of signatures; and when the comparison yields a match: generate an intrusion alert, the intrusion alert comprising the anomalous event data; and send the intrusion alert to a security monitoring system remote from the intrusion detection system (Deardorff et al. abstract, Fig. 1, [0005], [0047]-[0053], [0056]-[0057], [0067]-[0069], [0073], [0084], [0087]-[0089], [0096] and [0109]-[0115], discloses detecting malicious activity and comparing this activity to a database to determine if it is indeed malicious. If it is indeed considered malicious, an alert is issue. The MD5 hash is used for comparisons to determine if an intrusion has happened. The MD5 hash produces a smaller version of the data and therefore has compressive properties. Deardorff further discloses that the user device that receives the alert and the virtual security appliances can be together or located on different devices [0057]. Deardorf et al. does not discloses if the disclosed network data can be compressed, however Vadlakonda et al. discloses that having network data being compressed in a WAN (also a WAN is disclosed in Deardorf et al. [0061]) compressing network data reduces latency and improves bandwidth (background of invention.). Therefore the combination discloses that the network data can be compressed, the MD5 hash doesn’t care if data is compressed or not and can be used in the detection of malicious activity or the data can be decompressed first, the claims don’t require the data to be compared in compressed form. Vadlakonda et al. discloses that the compression can be dictionary based compression with sends references to code blocks, thus teaching a library (dictionary) with references being sent (codewords) to retrieve actual blocks of data (sourceblocks).).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the Deardorf et al. reference to have the network data being compressed, because compressing network data reduces latency and improves bandwidth (Vadlakonda et al.: background of invention.).
Consider claim 4, Deardorf et al. in view of Vadlakonda et al. discloses the system of claim 1, wherein one of either the anomalous event data, the one or more codewords, or the plurality of signatures are encrypted into secure representations of the same information (Deardorff et al. abstract, [0005], [0047]-[0053], [0067]-[0069], [0073], [0084], [0087]-[0089], [0096] and [0109]-[0115], an MD5 hash can be used.).
Claims 5 and 8 are the method claims to system claims 1 and 4 above and are rejected in the same manner.
Claim(s) 2, 3, 6 and 7 is/are rejected under 35 U.S.C. 103 as being unpatentable over Deardorf et al. (US 2021/0352092) and Vadlakonda et al. (US 7,953,881) as applied to claims 1 and 5 above, and further in view of McHugh et al. (US 2022/0171857).
Consider claim 2, Deardorf et al. in view of Vadlakonda et al. discloses the system of claim 1, and further discusses using simulations and iteratively training the system to better detect malicious activity while decreasing false positives (Deardorff et al. abstract, [0005], [0047]-[0053], [0067]-[0069], [0073], [0084], [0087]-[0089], [0096] and [0109]-[0115]), however Deardorff et al. does not explicitly state that a machine learning system is used during this process. But, McHugh et al. teaches a monitoring system for detecting security exploits that uses a RNN deep learning model to detect security exploits (abstract, summary of invention, [0018]- [0020]).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the Deardorf et al. reference to include predictive machine learning to perform the simulation and iterative training as described, because RNN deep learning models are an iterative neural network that remembers previous inputs and allows for the capture of context and relationships within sequences of data, making them ideal for operations where understanding the order/relationships of information is crucial.
Consider claim 3, Deardorf et al. in view of Vadlakonda et al. discloses the system of claim 1, and further discusses using simulations and iteratively training the system to better detect malicious activity while decreasing false positives (Deardorff et al. abstract, [0005], [0047]-[0053], [0067]-[0069], [0073], [0084], [0087]-[0089], [0096] and [0109]-[0115]), however Deardorff et al. does not explicitly state that the anomalous event data, the one or more codewords, and the plurality of signatures are processed through a predictive machine learning system that predicts whether an intrusion will be present based on the anomalous event data, the one or more codewords, and the plurality of signatures. But, McHugh et al. teaches a monitoring system for detecting security exploits that uses a RNN deep learning model to detect security exploits using current and historical measured data (abstract, summary of invention, [0018]-[0020]).
It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claimed invention to modify the Deardorf et al. reference to include predictive machine learning to perform the simulation and iterative training as described, because RNN deep learning models are an iterative neural network that remembers previous inputs and allows for the capture of context and relationships within sequences of data, making them ideal for operations where understanding the order/relationships of information is crucial.
Claims 6 and 7 are the method claims to system claims 2 and 3 above and are rejected in the same manner.
Response to Arguments
Applicant's arguments filed 4/13/2026 have been fully considered but they are not persuasive. The arguments pertain to the claim amendments, which include the previous limitations presented in the last amendment but now corrected, which have been addressed in the appropriate claim rejections above. The amendments have overcome the 112 issues and therefore the 112 rejections have been removed.
Conclusion
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MICHAEL ALSIP whose telephone number is (571)270-1182. The examiner can normally be reached M-F 9-5.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Kenneth M. Lo can be reached on (571) 272-9774. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MICHAEL ALSIP/ Primary Examiner, Art Unit 2136