Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Response to Amendments / Arguments
Regarding the rejection(s) of claims under 35 USC 103:
Applicant’s arguments, field 04/09/2026, in view of the amended claims, have been fully considered and are persuasive. Therefore the rejection has been withdrawn, however upon further review the rejection is maintained under Zahm (US 20230222393 A1, referred to as Zahm).
DETAILED ACTION
This is a reply to the application filed on 04/09/2026, in which, claims 1-20 are pending. Claims 1, 11, and 20 are independent.
When making claim amendments, the applicant is encouraged to consider the references in their entireties, including those portions that have not been cited by the examiner and their equivalents as they may most broadly and appropriately apply to any particular anticipated claim amendments.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 3, 5-7, 11, 13, 15-17 and 20 are rejected under 35 U.S.C. 103 as being unpatentable over Schneider et al. (US 20250013441 A1, referred to as Schneider), in view of Grover et al. (US 20240259347 A1, referred to as Grover) in further view of Zahm (US 20230222393 A1, referred to as Zahm)
In reference to claim 1, A computer-implemented method for implementing security policies in a data processing system (Schneider: [0003], [0022] and [0033] Provides for a computer-implemented method for implementing security policies in a data processing system.) generating at least one first large language model (LLM) tagging prompt, based on a request information, which requests a security semantic tagging operation by the LLM (Schneider: [0025] and [0044] Provides for generating prompts to LLMs for policy identification (semantic tagging) based on function signatures and node transitions (extracted request information).) submitting the at least one first LLM tagging prompt to a LLM for processing (Schneider: [0025], [0044] and [0077] Provides for submitting function signatures and node state transitions as inputs to LLMs (submitting tagging prompts) for policy analysis processing.) receiving at least one response to the at least one first LLM tagging prompt from the LLM, wherein the at least one response specifies one or more security semantic tags applicable to the request (Schneider: [0026] and [0045] Provides for the LLM identifing applicable security policies and controls (security semantic tags) for specific function signatures and code segments (applicable to the request).) correlating the one or more security semantic tags with one or more matching predefined security policies (Schneider: [0043]-[0045] Provides for correlating LLM-identified information (function signatures) with predefined security policies through a policy mapper component.) generating an output based on the one or more security semantic tags and the one or more matching predefined security policies (Schneider: [0029], [0048] and [0058] Provides for generating concrete outputs (policy-compliant code) based on LLM-identified policies and predefined security requirements.
Schneider does not explicitly teach receiving a request for an application or application programming interface (API) of the data processing system, extracting request information from the request and Wherein the request information is extracted request information. However, Grover discloses: receiving a request for an application or application programming interface (API) of the data processing system (Grover: [0017] and [0021] Provides for receiving HTTP requests in a data processing system for security analysis. Explicitly describes receiving requests for applications/APIs.) Extracting request information from the request and Wherein the request information is extracted request information (Grover: [0021] and [0040] Provides for extracting multiple parts from HTTP requests (RequestURI, Referer-Path, User-Agent, Content-Type, Body, headers). Teaching performing extraction of request components for downstream security analysis.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Schneider, which provides a computer-implemented method for implementing security policies using large language models to identify and tag security requirements and correlate them with predefined policies, with the teachings of Grover, which introduces receiving API or application requests and extracting specific information from those requests for security processing. One of ordinary skill in the art would recognize the ability to incorporate Grover's request handling and information extraction capabilities into Schneider's LLM-based security policy system to enable real-time security policy enforcement. One of ordinary skill in the art would be motivated to make this modification in order to create a dynamic security system that can analyze actual incoming requests rather than static code.
Schneider in view of Grover does not explicitly teach wherein the LLM operates on the at least one first LLM tagging prompt in a zero-shot manner and is not pre-trained for security semantic tagging of request. However, Zahm discloses:
Wherein the LLM operates on the at least one first LLM tagging prompt in a zero-shot manner and is not pre-trained for security semantic tagging of request (Zahm: claim 1 and [0003]-[0019] Provides for "zero-shot prompting" against a general pre-trained external LLM that has not been fine-tuned for the specific downstream task.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Schneider in view of Grover, which together provide a method for implementing security policies using LLM-based semantic tagging of extracted API request information, with the teachings of Zahm, which introduces operating a general pre-trained LLM in a zero-shot manner without task-specific fine-tuning for downstream security applications. One of ordinary skill in the art would recognize the ability to incorporate Zahm's zero-shot prompting approach into the combined security policy system to eliminate the need for specialized model training. One of ordinary skill in the art would be motivated to make this modification in order to reduce the significant cost and time associated with fine-tuning specialized security models by leveraging the broad knowledge already embedded in general-purpose LLMs.
In reference to claim 3, The computer-implemented method of claim 1, wherein the request information comprises header information specifying at least one of a method and a path (Grover: [0021] and [0040] Provides for extracting and processing header information including RequestURI (which contains the path) and other headers (which would include the HTTP method).)
In reference to claim 5, The computer-implemented method of claim 1, wherein the output comprises content specifying the one or more matching predefined security policies (Schneider: [0026], [0045], [0048]-[0049] and [0058] Provides for generating output that specifies security policies and policy-compliant solutions. Grover: [0039]-[0040] Provides for outputs that reference and trigger specific WAF rules based on the ML classification results.)
In reference to claim 6, The computer-implemented method of claim 1, further comprising automatically executing the one or more matching predefined security policies on the request to determine if the request is in compliance with the one or more matching predefined security policies, wherein the output comprises an indicator of whether the request is in compliance with the one or more matching predefined security policies (Schneider: [0027] and [0046]-[0047] Provides for automatically executing policy compliance operations, determining compliance/non-compliance with security policies, and generating indicators of compliance status. Grover: [0009] and [0018]-[0019] Provides for automatic execution of traffic processing rules based on ML classification results to determine compliance/non-compliance (malicious vs. non-malicious).)
In reference to claim 7, The computer-implemented method of claim 6, wherein automatically executing the one or more matching predefined security policies comprises: appending the one or more security semantic tags to a header of the request to thereby generate an extended request (Grover: [0039] Provides for appending ML output (scores) to request headers.) forwarding the extended request to a security policy enforcement system, wherein correlating the one or more security semantic tags with one or more matching predefined security policies is performed by the security policy enforcement system based on the one or more security semantic tags in the extended request (Grover: [0018] and [0039] Provides for forwarding the enhanced request (with appended scores in headers) to a separate rules engine (security policy enforcement system) that performs the actual policy correlation and enforcement based on the ML classification results in the extended request.)
In reference to claim 11, A computer program product comprising a computer readable storage medium having a computer readable program stored therein, wherein the computer readable program, when executed in a data processing system (Schneider: [0003], [0022] and [0033] Provides for a computer-implemented method for implementing security policies in a data processing system.) generating at least one first large language model (LLM) tagging prompt, based on a request information, which requests a security semantic tagging operation by the LLM (Schneider: [0025] and [0044] Provides for generating prompts to LLMs for policy identification (semantic tagging) based on function signatures and node transitions (extracted request information).) submitting the at least one first LLM tagging prompt to a LLM for processing (Schneider: [0025], [0044] and [0077] Provides for submitting function signatures and node state transitions as inputs to LLMs (submitting tagging prompts) for policy analysis processing.) receiving at least one response to the at least one first LLM tagging prompt from the LLM, wherein the at least one response specifies one or more security semantic tags applicable to the request (Schneider: [0026] and [0045] Provides for the LLM identifing applicable security policies and controls (security semantic tags) for specific function signatures and code segments (applicable to the request).) correlating the one or more security semantic tags with one or more matching predefined security policies (Schneider: [0043]-[0045] Provides for correlating LLM-identified information (function signatures) with predefined security policies through a policy mapper component.) generating an output based on the one or more security semantic tags and the one or more matching predefined security policies (Schneider: [0029], [0048] and [0058] Provides for generating concrete outputs (policy-compliant code) based on LLM-identified policies and predefined security requirements.
Schneider does not explicitly teach receiving a request for an application or application programming interface (API) of the data processing system, extracting request information from the request and Wherein the request information is extracted request information. However, Grover discloses: receiving a request for an application or application programming interface (API) of the data processing system (Grover: [0017] and [0021] Provides for receiving HTTP requests in a data processing system for security analysis. Explicitly describes receiving requests for applications/APIs.) Extracting request information from the request and Wherein the request information is extracted request information (Grover: [0021] and [0040] Provides for extracting multiple parts from HTTP requests (RequestURI, Referer-Path, User-Agent, Content-Type, Body, headers). Teaching performing extraction of request components for downstream security analysis.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Schneider, which provides a computer-implemented method for implementing security policies using large language models to identify and tag security requirements and correlate them with predefined policies, with the teachings of Grover, which introduces receiving API or application requests and extracting specific information from those requests for security processing. One of ordinary skill in the art would recognize the ability to incorporate Grover's request handling and information extraction capabilities into Schneider's LLM-based security policy system to enable real-time security policy enforcement. One of ordinary skill in the art would be motivated to make this modification in order to create a dynamic security system that can analyze actual incoming requests rather than static code.
Schneider in view of Grover does not explicitly teach wherein the LLM operates on the at least one first LLM tagging prompt in a zero-shot manner and is not pre-trained for security semantic tagging of request. However, Zahm discloses:
Wherein the LLM operates on the at least one first LLM tagging prompt in a zero-shot manner and is not pre-trained for security semantic tagging of request (Zahm: claim 1 and [0003]-[0019] Provides for "zero-shot prompting" against a general pre-trained external LLM that has not been fine-tuned for the specific downstream task.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Schneider in view of Grover, which together provide a method for implementing security policies using LLM-based semantic tagging of extracted API request information, with the teachings of Zahm, which introduces operating a general pre-trained LLM in a zero-shot manner without task-specific fine-tuning for downstream security applications. One of ordinary skill in the art would recognize the ability to incorporate Zahm's zero-shot prompting approach into the combined security policy system to eliminate the need for specialized model training. One of ordinary skill in the art would be motivated to make this modification in order to reduce the significant cost and time associated with fine-tuning specialized security models by leveraging the broad knowledge already embedded in general-purpose LLMs.
In reference to claim 13, The computer program product of claim 11, wherein the request information comprises header information specifying at least one of a method and a path (Grover: [0021] and [0040] Provides for extracting and processing header information including RequestURI (which contains the path) and other headers (which would include the HTTP method).)
In reference to claim 15, The computer program product of claim 11, wherein the output comprises content specifying the one or more matching predefined security policies (Schneider: [0026], [0045], [0048]-[0049] and [0058] Provides for generating output that specifies security policies and policy-compliant solutions. Grover: [0039]-[0040] Provides for outputs that reference and trigger specific WAF rules based on the ML classification results.)
In reference to claim 16, The computer program product of claim 11, further comprising automatically executing the one or more matching predefined security policies on the request to determine if the request is in compliance with the one or more matching predefined security policies, wherein the output comprises an indicator of whether the request is in compliance with the one or more matching predefined security policies (Schneider: [0027] and [0046]-[0047] Provides for automatically executing policy compliance operations, determining compliance/non-compliance with security policies, and generating indicators of compliance status. Grover: [0009] and [0018]-[0019] Provides for automatic execution of traffic processing rules based on ML classification results to determine compliance/non-compliance (malicious vs. non-malicious).)
In reference to claim 17, The computer program product of claim 16, wherein automatically executing the one or more matching predefined security policies comprises: appending the one or more security semantic tags to a header of the request to thereby generate an extended request (Grover: [0039] Provides for appending ML output (scores) to request headers.) forwarding the extended request to a security policy enforcement system, wherein correlating the one or more security semantic tags with one or more matching predefined security policies is performed by the security policy enforcement system based on the one or more security semantic tags in the extended request (Grover: [0018] and [0039] Provides for forwarding the enhanced request (with appended scores in headers) to a separate rules engine (security policy enforcement system) that performs the actual policy correlation and enforcement based on the ML classification results in the extended request.)
In reference to claim 20, An apparatus comprising: at least one processor; and at least one memory coupled to the at least one processor, wherein the at least one memory comprises instructions which, when executed by the at least one processor (Schneider: [0003], [0022] and [0033] Provides for a computer-implemented method for implementing security policies in a data processing system.) generating at least one first large language model (LLM) tagging prompt, based on a request information, which requests a security semantic tagging operation by the LLM (Schneider: [0025] and [0044] Provides for generating prompts to LLMs for policy identification (semantic tagging) based on function signatures and node transitions (extracted request information).) submitting the at least one first LLM tagging prompt to a LLM for processing (Schneider: [0025], [0044] and [0077] Provides for submitting function signatures and node state transitions as inputs to LLMs (submitting tagging prompts) for policy analysis processing.) receiving at least one response to the at least one first LLM tagging prompt from the LLM, wherein the at least one response specifies one or more security semantic tags applicable to the request (Schneider: [0026] and [0045] Provides for the LLM identifing applicable security policies and controls (security semantic tags) for specific function signatures and code segments (applicable to the request).) correlating the one or more security semantic tags with one or more matching predefined security policies (Schneider: [0043]-[0045] Provides for correlating LLM-identified information (function signatures) with predefined security policies through a policy mapper component.) generating an output based on the one or more security semantic tags and the one or more matching predefined security policies (Schneider: [0029], [0048] and [0058] Provides for generating concrete outputs (policy-compliant code) based on LLM-identified policies and predefined security requirements.
Schneider does not explicitly teach receiving a request for an application or application programming interface (API) of the data processing system, extracting request information from the request and Wherein the request information is extracted request information. However, Grover discloses: receiving a request for an application or application programming interface (API) of the data processing system (Grover: [0017] and [0021] Provides for receiving HTTP requests in a data processing system for security analysis. Explicitly describes receiving requests for applications/APIs.) Extracting request information from the request and Wherein the request information is extracted request information (Grover: [0021] and [0040] Provides for extracting multiple parts from HTTP requests (RequestURI, Referer-Path, User-Agent, Content-Type, Body, headers). Teaching performing extraction of request components for downstream security analysis.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Schneider, which provides a computer-implemented method for implementing security policies using large language models to identify and tag security requirements and correlate them with predefined policies, with the teachings of Grover, which introduces receiving API or application requests and extracting specific information from those requests for security processing. One of ordinary skill in the art would recognize the ability to incorporate Grover's request handling and information extraction capabilities into Schneider's LLM-based security policy system to enable real-time security policy enforcement. One of ordinary skill in the art would be motivated to make this modification in order to create a dynamic security system that can analyze actual incoming requests rather than static code.
Schneider in view of Grover does not explicitly teach wherein the LLM operates on the at least one first LLM tagging prompt in a zero-shot manner and is not pre-trained for security semantic tagging of request. However, Zahm discloses:
Wherein the LLM operates on the at least one first LLM tagging prompt in a zero-shot manner and is not pre-trained for security semantic tagging of request (Zahm: claim 1 and [0003]-[0019] Provides for "zero-shot prompting" against a general pre-trained external LLM that has not been fine-tuned for the specific downstream task.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Schneider in view of Grover, which together provide a method for implementing security policies using LLM-based semantic tagging of extracted API request information, with the teachings of Zahm, which introduces operating a general pre-trained LLM in a zero-shot manner without task-specific fine-tuning for downstream security applications. One of ordinary skill in the art would recognize the ability to incorporate Zahm's zero-shot prompting approach into the combined security policy system to eliminate the need for specialized model training. One of ordinary skill in the art would be motivated to make this modification in order to reduce the significant cost and time associated with fine-tuning specialized security models by leveraging the broad knowledge already embedded in general-purpose LLMs.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 2, 9-10, 12 and 19 are rejected under 35 U.S.C. 103 as being unpatentable over Schneider et al. (US 20250013441 A1, referred to as Schneider), in view of Grover et al. (US 20240259347 A1, referred to as Grover) in further view of Zahm (US 20230222393 A1, referred to as Zahm) in further view of Wu et al. (US 20250047578 A1, referred to as Wu).
In reference to claim 2, The computer-implemented method of claim 1, wherein each first LLM tagging prompt in the at least one first LLM tagging prompt comprises a system prompt portion that is static across a plurality of LLM tagging prompts (Wu: [0135]-[0139] and [0147] Provides for static prompt fragments that are permanent parts of prompt templates and are common across multiple prompts.) which specifies at least one predefined security semantic classification, and a request specific prompt portion that is specific to the extracted request information (Wu: [0140]-[0142] Provides for the system includes both predefined classification guidelines in prompt fragments and event-specific information portions.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Schneider in view of Grover, which together provide a method for implementing security policies using LLM-based tagging of extracted request information, with the teachings of Wu, which introduces structured prompts comprising static template fragments that remain constant across multiple prompts and dynamic portions specific to individual events. One of ordinary skill in the art would recognize the ability to incorporate Wu's dual-component prompt structure into the combined security policy system to improve efficiency and consistency in LLM interactions. One of ordinary skill in the art would be motivated to make this modification in order to optimize LLM processing by maintaining consistent security classification guidelines in static prompt portions while varying only the request-specific details.
In reference to claim 9, The computer-implemented method of claim 1, wherein the at least one first LLM tagging prompt comprises a plurality of first LLM tagging prompts, each first LLM tagging prompt being associated with a different classification of request type (Wu: [0120] and [0166]-[0169] Provides for using different prompt templates directed to particular event types, and selecting different action agents based on event characteristics.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Schneider in view of Grover, which together provide a method for implementing security policies using LLM-based tagging of extracted request information, with the teachings of Wu, which introduces using different prompt templates directed to particular event types and selecting different processing approaches based on event characteristics. One of ordinary skill in the art would recognize the ability to incorporate Wu's request-type-specific prompt selection into the combined security policy system to provide more targeted and accurate security analysis. One of ordinary skill in the art would be motivated to make this modification in order to improve security tagging accuracy by using specialized prompts tailored to different types of requests.
In reference to claim 10, The computer-implemented method of claim 1, further comprising submitting at least one subsequent LLM tagging prompt, based on the at least one first LLM tagging prompt, but with a relatively larger token size than the at least one first LLM tagging prompt, to thereby generate reasoning information, and storing the reasoning information in association with an indicator of the at least one first LLM tagging prompt in a database (Wu: [0105]-[0106] and [0122]-[0127] Provides for generating subsequent prompts based on initial responses, with additional information included (action response information), which creates larger/more detailed prompts.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Schneider in view of Grover, which together provide a method for implementing security policies using LLM-based tagging of extracted request information, with the teachings of Wu, which introduces generating subsequent prompts with additional information based on initial responses and storing the expanded results for future reference. One of ordinary skill in the art would recognize the ability to incorporate Wu's iterative prompt expansion and reasoning storage approach into the combined security policy system to enhance decision transparency and create learning capabilities. One of ordinary skill in the art would be motivated to make this modification in order to improve security policy decisions by generating detailed reasoning that explains why specific security tags were applied.
In reference to claim 12, The computer program product of claim 11, wherein each first LLM tagging prompt in the at least one first LLM tagging prompt comprises a system prompt portion that is static across a plurality of LLM tagging prompts (Wu: [0135]-[0139] and [0147] Provides for static prompt fragments that are permanent parts of prompt templates and are common across multiple prompts.) which specifies at least one predefined security semantic classification, and a request specific prompt portion that is specific to the extracted request information (Wu: [0140]-[0142] Provides for the system includes both predefined classification guidelines in prompt fragments and event-specific information portions.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Schneider in view of Grover, which together provide a method for implementing security policies using LLM-based tagging of extracted request information, with the teachings of Wu, which introduces structured prompts comprising static template fragments that remain constant across multiple prompts and dynamic portions specific to individual events. One of ordinary skill in the art would recognize the ability to incorporate Wu's dual-component prompt structure into the combined security policy system to improve efficiency and consistency in LLM interactions. One of ordinary skill in the art would be motivated to make this modification in order to optimize LLM processing by maintaining consistent security classification guidelines in static prompt portions while varying only the request-specific details.
In reference to claim 19, The computer program product of claim 11, wherein the at least one first LLM tagging prompt comprises a plurality of first LLM tagging prompts, each first LLM tagging prompt being associated with a different classification of request type (Wu: [0120] and [0166]-[0169] Provides for using different prompt templates directed to particular event types, and selecting different action agents based on event characteristics.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Schneider in view of Grover, which together provide a method for implementing security policies using LLM-based tagging of extracted request information, with the teachings of Wu, which introduces using different prompt templates directed to particular event types and selecting different processing approaches based on event characteristics. One of ordinary skill in the art would recognize the ability to incorporate Wu's request-type-specific prompt selection into the combined security policy system to provide more targeted and accurate security analysis. One of ordinary skill in the art would be motivated to make this modification in order to improve security tagging accuracy by using specialized prompts tailored to different types of requests.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 4, 8, 14, and 18 are rejected under 35 U.S.C. 103 as being unpatentable over Schneider et al. (US 20250013441 A1, referred to as Schneider), in view of Grover et al. (US 20240259347 A1, referred to as Grover) in further view of Zahm (US 20230222393 A1, referred to as Zahm) in further view of Feillet et al. (US 20150206075 A1, referred to as Feillet).
In reference to claim 4, The computer-implemented method of claim 3, wherein the method and path are concatenated and input to a hashing function to generate a hash value for a key value store of a tagging cache (Feillet: [0028]-[0034] Provides for concatenating request parameters/information and input them to key generation functions (hashing functions) to create keys for cache storage.) wherein the hash value is stored in the tagging cache in association with the one or more security semantic tags (Feillet: [0031]-[0035] Provides for storing generated hash/key values in cache associated with the analysis results.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Schneider in view of Grover, which together provide a method for implementing security policies using LLM-based tagging of extracted request information including method and path details, with the teachings of Feillet, which introduces concatenating request parameters and applying hashing functions to generate cache keys, then storing these hash values in cache associated with analysis results. One of ordinary skill in the art would recognize the ability to incorporate Feillet's hash-based caching approach into the combined security policy system to improve performance through intelligent result reuse. One of ordinary skill in the art would be motivated to make this modification in order to significantly reduce LLM processing overhead by caching security semantic tags for previously analyzed request patterns.
In reference to claim 8, The computer-implemented method of claim 1, further comprising: performing a cache lookup in a tagging cache based on the request information extracted from the request to determine if there is a matching entry in the tagging cache (Feillet: [0035]-[0038] Provides for performing cache lookups based on extracted request information (parameters) to determine if there's a matching cache entry.) in response to there being a cache hit in the tagging cache, retrieving one or more corresponding cached security semantic tags from the matching entry to be the one or more security semantic tags (Feillet: [0038]-[0040] Provides for retrieving cached results (security semantic tags vs. decisions) from matching cache entries when there's a cache hit.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Schneider in view of Grover, which together provide a method for implementing security policies using LLM-based tagging of extracted request information, with the teachings of Feillet, which introduces performing cache lookups based on request parameters and retrieving cached results when matching entries are found. One of ordinary skill in the art would recognize the ability to incorporate Feillet's cache lookup and retrieval mechanism into the combined security policy system to eliminate redundant LLM processing for previously analyzed requests. One of ordinary skill in the art would be motivated to make this modification in order to dramatically improve system performance by checking for existing security semantic tags.
In reference to claim 14, The computer program product of claim 13, wherein the method and path are concatenated and input to a hashing function to generate a hash value for a key value store of a tagging cache (Feillet: [0028]-[0034] Provides for concatenating request parameters/information and input them to key generation functions (hashing functions) to create keys for cache storage.) wherein the hash value is stored in the tagging cache in association with the one or more security semantic tags (Feillet: [0031]-[0035] Provides for storing generated hash/key values in cache associated with the analysis results.) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Schneider in view of Grover, which together provide a method for implementing security policies using LLM-based tagging of extracted request information including method and path details, with the teachings of Feillet, which introduces concatenating request parameters and applying hashing functions to generate cache keys, then storing these hash values in cache associated with analysis results. One of ordinary skill in the art would recognize the ability to incorporate Feillet's hash-based caching approach into the combined security policy system to improve performance through intelligent result reuse. One of ordinary skill in the art would be motivated to make this modification in order to significantly reduce LLM processing overhead by caching security semantic tags for previously analyzed request patterns.
In reference to claim 18, The computer program product of claim 11, further comprising: performing a cache lookup in a tagging cache based on the request information extracted from the request to determine if there is a matching entry in the tagging cachee (Feillet: [0035]-[0038] Provides for performing cache lookups based on extracted request information (parameters) to determine if there's a matching cache entry.) in response to there being a cache hit in the tagging cache, retrieving one or more corresponding cached security semantic tags from the matching entry to be the one or more security semantic tags (Feillet: [0038]-[0040] Provides for retrieving cached results (security semantic tags vs. decisions) from matching cache entries when there's a cache hit.)
It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teachings of Schneider in view of Grover, which together provide a method for implementing security policies using LLM-based tagging of extracted request information, with the teachings of Feillet, which introduces performing cache lookups based on request parameters and retrieving cached results when matching entries are found. One of ordinary skill in the art would recognize the ability to incorporate Feillet's cache lookup and retrieval mechanism into the combined security policy system to eliminate redundant LLM processing for previously analyzed requests. One of ordinary skill in the art would be motivated to make this modification in order to dramatically improve system performance by checking for existing security semantic tags.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. See PTO-892.
Applicant’s amendment necessitated the new ground(s) of rejection presented in this office action. Accordingly, THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to AIDAN EDWARD SHAUGHNESSY whose telephone number is (703)756-1423. The examiner can normally be reached on Monday-Friday from 7:30am to 5pm.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Jeffrey Nickerson, can be reached at telephone number (469) 295-9235. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of an application may be obtained from Patent Center and the Private Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from Patent Center or Private PAIR. Status information for unpublished applications is available through Patent Center and Private PAIR for authorized users only. Should you have questions about access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free).
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) Form at https://www.uspto.gov/patents/usptoautomated-interview-request-air-form.
/A.E.S./Examiner, Art Unit 2432
/Jeffrey Nickerson/Supervisory Patent Examiner, Art Unit 2432