Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
DETAILED ACTION
1. This action is in response to the amendment and argument field on 21 April 2026.
2. Claims 1, 10 and 19 have been amended.
3. Claims 1-20 remain Pending and Rejected.
Responses to the Argument
4. The applicant’s arguments filed on 21 April 2026 are moot in view of new ground of rejection rendered.
Claim Rejections - 35 USC § 103
5. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-20 are rejected under 35 U.S.C §103 as being unpatentable over Li et al. (CN Publication No. CN 108023882), hereinafter Li and in view of Spain et al. (US Publication No. 20240362322), hereinafter Spain and in view of Ortiz et al. (US Publication number 20210406386), herein after Ortiz Aand in view of Avi Chesla (US publication no. 20170063930), hereinafter Chesla.
Regarding claim 1:
receiving, by one or more processors, one or more indicators of a data leak occurring at one or more nodes of a network (Li, page 14, para.1, page 12, para.4), wherein receiving the network flow data so as to complete the transmission of data information.
Li in view of Spain and Ortiz does not explicitly suggest, wherein the indicators of the data leak includes one or more signal or data point that suggest unauthorized access, disclosure, or exposure of data; however in a same field of endeavor Chesla discloses this limitation (Chesla, ¶37, ¶60).
It would have been obvious to one of ordinary skill in the art at the time the invention was filed to include the method of determining data leak and prevention of Li in view of Spain and Ortiz with the method of generating leak indicator disclosed in Chesla to identify compromised device/mode, stated by Chesla at para.37.
causing, by the one or more processors and via a machine-learning model, an identification of one or more compromised nodes within the network based on the one or more indicators of a data leak (Li, page 9, para.7, page 14, para.2), wherein real-time identification of sensitive data and feedback to the access node detecting node according to the data anti-leakage system control platform sends a detection strategy combined with sensitive data model.
Li does not explicitly suggest, wherein the machine-learning model has been trained on an architecture, layout, or topology of the network and on one or more network data flow; however, in a same field of endeavor Spain discloses this limitation (Spain, ¶57), wherein machine learning model may include a generative adversarial network trained to generate network topologies or layouts based on network topologies or layouts discovered from captured packet data.
It would have been obvious to one of ordinary skill in the art at the time the invention was filed to include the method of determining data leak and prevention of Li with the method of access control and generating alarm disclosed in Spain secure data, stated by Spain at para.56.
receiving from the machine-learning model, by the one or more processors, the identification of the one or more compromised nodes (Li, Abstract).
Li in view of Spain does not explicitly suggest, modifying, by the one or more processors, access permissions at the one or more identified compromised nodes based on a user permission schema or pre-determined access rules, in response to the data leak; however, in a same field of endeavor Ortiz discloses this limitation (Ortiz, ¶108, ¶215), Where access permissions are to be revoked (e.g., in the event of an identified breach by a partner or the dissolution of a combined marketing campaign), the system is configured to update roles.
Li in view Spain does not explicitly suggest, and causing, by the one or more processors, a generation of a notification regarding the data leak and the modifications of access permissions to one or more users associated with the network; however, in a same field of endeavor Spain discloses this limitation (Ortiz, ¶167, ¶215) wherein security action comprises blocking the content, quarantining the content, alerting an administrator, alerting an analyst, or designating the content for additional analysis
It would have been obvious to one of ordinary skill in the art at the time the invention was filed to include the method of determining data leak and prevention of Li in view of Spain with the method of access control and generating alarm disclosed in Ortiz secure data, stated by Ortiz at para.124.
Regarding claim 2:
Li in view of Spain does not explicitly suggest, wherein the machine-learning model has further been trained on historical data flow throughout the network and one or more images of the architecture, layout, or topology of the network to identify associations between data at a first node and data at one or more second nodes however, in a same field of endeavor Ortiz discloses this limitation (Ortiz, ¶108).
Same motivation for combining the respective features of Li in view of Spain and Ortiz applies herein, as discussed as above.
Regarding claim 3:
Li in view of Spain does not explicitly suggest, wherein modifying access permissions includes restricting access to the identified one or more compromised nodes for one or more users or user groups; however, in a same field of endeavor Ortiz discloses this limitation (Ortiz, ¶108).
Same motivation for combining the respective features of Li in view of Spain and Ortiz applies herein, as discussed as above.
Regarding claim 4:
Li does not explicitly suggest, further comprising analyzing, by the machine-learning model, the user permission schema to determine one or more modification for the access permissions; however, in a same field of endeavor Spain discloses this limitation (Spain, ¶111, ¶108).
Same motivation for combining the respective features of Li in view of Spain and Ortiz applies herein, as discussed as above.
Regarding claim 5:
Li in view Spain does not explicitly suggest, wherein the notification includes details about the identified one or more compromised nodes, a parameter of the data leak, and one or more modifications made to access permissions; however, in a same field of endeavor Ortiz discloses this limitation (Ortiz, ¶107-108).
Same motivation for combining the respective features of Li in view of Spain and Ortiz applies herein, as discussed as above.
Regarding claim 6:
further comprising rolling back one or more impacted nodes to a previous state that is unaffected by the data leak (Li, page 12, para.2).
Regarding claim 7:
wherein the rolling back includes reverting to one or more prior versions of logs or applications at the one or more impacted nodes (Li, page 12, para.2).
Regarding claim 8:
further comprising presenting a visual representation of the network, indicating the compromised nodes, the modifications to access permissions, and any rollbacks performed (Li, page 8, para.9).
Regarding claim 9:
wherein the machine-learning model predicts one or more additional nodes potentially impacted by the data leak, and the one or more processors generates one or more suggested preventive modifications to access permissions at the one or more additional nodes (Li, page 11, para.3).
Regarding claim 10:
receiving, by one or more processors, one or more indicators of a data leak occurring at one or more nodes of a network (Li, page 14, para.1, page 12, para.4), wherein receiving the network flow data so as to complete the transmission of data information.
Li in view of Spain and Ortiz does not explicitly suggest, wherein the indicators of the data leak includes one or more signal or data point that suggest unauthorized access, disclosure, or exposure of data; however in a same field of endeavor Chesla discloses this limitation (Chesla, ¶37, ¶60).
It would have been obvious to one of ordinary skill in the art at the time the invention was filed to include the method of determining data leak and prevention of Li in view of Spain and Ortiz with the method of generating leak indicator disclosed in Chesla to identify compromised device/mode, stated by Chesla at para.37.
causing, by the one or more processors and via a machine-learning model, an identification of one or more compromised nodes within the network based on the one or more indicators of a data leak (Li, page 9, para.7, page 14, para.2), wherein real-time identification of sensitive data and feedback to the access node detecting node according to the data anti-leakage system control platform sends a detection strategy combined with sensitive data model.
Li does not explicitly suggest, wherein the machine-learning model has been trained on an architecture, layout, or topology of the network and on one or more network data flow; however, in a same field of endeavor Spain discloses this limitation (Spain, ¶57), wherein machine learning model may include a generative adversarial network trained to generate network topologies or layouts based on network topologies or layouts discovered from captured packet data.
It would have been obvious to one of ordinary skill in the art at the time the invention was filed to include the method of determining data leak and prevention of Li with the method of access control and generating alarm disclosed in Spain secure data, stated by Spain at para.56.
receiving from the machine-learning model, by the one or more processors, the identification of the one or more compromised nodes (Li, Abstract).
Li in view of Spain does not explicitly suggest, initiating, by the one or more processors, a remedial action, the remedial action including an automatic rollback of the one or more compromised nodes to a previous state unaffected by the data leak; however, in a same field of endeavor Ortiz discloses this limitation (Ortiz, ¶321), wherein The system can be configured to support a rollback-to-previous image operation in the event that needs.
Li in view of Spain does not explicitly suggest, and causing, by the one or more processors, a generation of a notification regarding the data leak and the remedial actions undertaken, including details of the rollbacks performed, to one or more users associated with the network; however, in a same field of endeavor Ortiz discloses this limitation (Ortiz, ¶237), wherein The system can be configured to support a rollback-to-previous image operation in the event that needs.
It would have been obvious to one of ordinary skill in the art at the time the invention was filed to include the method of determining data leak and prevention of Li in view of Spain with the method of access control and generating alarm disclosed in Ortiz secure data, stated by Ortiz at para.124.
Regarding claim 11:
Li in view of Spain does not explicitly suggest, wherein the machine-learning model has further been trained using historical data flow throughout the network and one or more images of the architecture, layout, or topology of the network; however, in a same field of endeavor Ortiz discloses this limitation (Ortiz, ¶108).
Same motivation for combining the respective features of Li in view of Spain and Ortiz applies herein, as discussed as above.
Regarding claim 12:
Li in view of Spain does not explicitly suggest, further comprising modifying access permissions at one or more identified compromised nodes in addition to the remedial action, based on a current user permission schema or pre-determined access rules; however, in a same field of endeavor Ortiz discloses this limitation (Ortiz, ¶105).
Same motivation for combining the respective features of Li in view of Spain and Ortiz applies herein, as discussed as above.
Regarding claim 11:
Li in view of Spain does not explicitly suggest, wherein the notification includes details about the one or more compromised nodes, one or more parameters of the data leak, and the one or more remedial action performed; however, in a same field of endeavor Ortiz discloses this limitation (Ortiz, ¶173).
Same motivation for combining the respective features of Li in view of Spain and Ortiz applies herein, as discussed as above.
Regarding claim 14:
wherein the remedial action is selectively applied to specific components or services of the one or more compromised nodes based on one or more parameter of the data leak (Li, page 3, para.4).
Regarding claim 15:
Li in view of Spain does not explicitly suggest, further comprising analyzing a user permission schema to determine potential vulnerabilities and to guide one or more remedial action; however, in a same field of endeavor Ortiz discloses this limitation (Ortiz, ¶105).
Same motivation for combining the respective features of Li in view of Spain and Ortiz applies herein, as discussed as above.
Regarding claim 16:
wherein the machine-learning model predicts additional nodes potentially impacted by the data leak and suggests preventive actions for the additional nodes (Li, page 11, para.3).
Regarding claim 17:
further comprising presenting a visual representation of the network, indicating the one or more compromised nodes and the remedial actions undertaken (Li, page 12, para.2).
Regarding claim 18:
wherein the remedial action includes restoring data from backups that predate the data leak (Li, page 14, para.2).
Regarding claim 19:
detecting, by the one or more processors, a data leak at one or more nodes of the network (Li, page 14, para.2).
Li in view of Spain and Ortiz does not explicitly suggest, wherein the indicators of the data leak includes one or more signal or data point that suggest unauthorized access, disclosure, or exposure of data; however in a same field of endeavor Chesla discloses this limitation (Chesla, ¶37, ¶60).
It would have been obvious to one of ordinary skill in the art at the time the invention was filed to include the method of determining data leak and prevention of Li in view of Spain and Ortiz with the method of generating leak indicator disclosed in Chesla to identify compromised device/mode, stated by Chesla at para.37.
identifying, by the one or more processors using a machine-learning model, one or more compromised nodes affected by the data leak (Li, page 9, para.7, page 14, para.2), wherein real-time identification of sensitive data and feedback to the access node detecting node according to the data anti-leakage system control platform sends a detection strategy combined with sensitive data model.
Li does not explicitly suggest, wherein the model is trained on a structure of the network and one or more data flow of the network; however, in a same field of endeavor Spain discloses this limitation (Spain, ¶57), wherein machine learning model may include a generative adversarial network trained to generate network topologies or layouts based on network topologies or layouts discovered from captured packet data.
It would have been obvious to one of ordinary skill in the art at the time the invention was filed to include the method of determining data leak and prevention of Li with the method of access control and generating alarm disclosed in Spain secure data, stated by Spain at para.56.
Li in view of Spain does not explicitly suggest, modifying, by the one or more processors, access permissions at the one or more compromised nodes based on an output of the machine-learning model, current user permissions, or predefined rules; however, in a same field of endeavor Ortiz discloses this limitation (Ortiz, ¶108, ¶215), Where access permissions are to be revoked (e.g., in the event of an identified breach by a partner or the dissolution of a combined marketing campaign), the system is configured to update roles.
Li in view of Spain does not explicitly suggest, performing, by the one or more processors, a remedial action to the one or more compromised nodes; ; however, in a same field of endeavor Ortiz discloses this limitation (Ortiz, ¶321), wherein The system can be configured to support a rollback-to-previous image operation in the event that needs.
Li in view of Spain does not explicitly suggest, and generating, by the one or more processors, a notification about the data leak, one or more modifications to access permissions, and the remedial actions, for one or more network users; however, in a same field of endeavor Ortiz discloses this limitation (Ortiz, ¶237), wherein The system can be configured to support a rollback-to-previous image operation in the event that needs.
Regarding claim 20:
Li in view of Spain does not explicitly suggest, wherein the remedial action includes rolling back the one or more compromised nodes to a previous state unaffected by the data leak, and wherein the modification of access permissions includes temporarily restricting access to sensitive data or services at the compromised nodes until the remedial action is completed; however, in a same field of endeavor Ortiz discloses this limitation (Ortiz, ¶173).
Same motivation for combining the respective features of Li in view of Spain and Ortiz applies herein, as discussed as above.
Conclusion
6. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the date of this final action.
The prior art made of record and not relied upon is considered pertinent to applicant’s disclosure (See form “PTO-892 Notice of reference cited).
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MONJUR RAHIM whose telephone number is (571)270-3890.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shewye Gelagay can be reached on 571-272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Monjur Rahim/
Patent Examiner
United States Patent and Trademark Office
Art Unit: 2436; Phone: 571.270.3890
E-mail: monjur.rahim@uspto.gov
Fax: 571.270.4890