DETAILED ACTION
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
The amendment filed 5/15/2026 has been placed of record in the file.
Claims 1, 8, 11, 13, and 18 have been amended.
Claims 2 and 12 have been canceled.
Claims 1, 3-11, and 13-20 are now pending.
The applicant’s arguments with respect to claims 1, 3-11, and 13-20 have been considered but are moot in view of the following new grounds of rejection.
Response to Amendment
Claims have been amended to further define the data entries. The amendment proves a change in scope to the independent claims as the independent claims now explicitly state that the data entries are related to cyber security events. However, none of the amended claims show a patentable distinction over the prior art as evidenced by the following new grounds of rejection.
Claim Rejections - 35 USC § 103
In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis (i.e., changing from AIA to pre-AIA ) for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status.
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1, 3-11, and 13-20 are rejected under 35 U.S.C. 103 as being unpatentable over Waplington et al. (U.S. Patent Application Publication Number 2024/0256168), hereinafter referred to as Waplington, in view of Lambert et al. (U.S. Patent Application Publication Number 2022/0035783), hereinafter referred to as Lambert.
Waplington disclosed techniques for correlating data records. In an analogous art, Lambert disclosed techniques for managing historical security data. Both systems are directed toward the ingestion and management of data records.
Regarding claim 1, Waplington discloses a computer system for ingesting data from multiple sources, the computer system comprising: one or more processors; and non-transitory computer-readable storage media encoding instructions which, when executed by the one or more processors, causes the computer system to: receive, from a plurality of data sources, data entries, the plurality of data sources including an external computing device and an application programming interface (paragraph 19, data records correlated across different instances with sources on different application servers on different network domains); determine an application for use of the data entries (paragraph 58, matches update event for target instance); transform the data entries for storage in a database (paragraph 61, modify received data records to create version for target instance); curate a history record of the data entries stored in the database (paragraph 34, correlation history), wherein the history record includes prior versions of the data entries that are rendered inactive upon storage of updated versions of the data entries (paragraph 67, each correlation entry includes history of changes); and refine the data entries for use with the application (paragraph 61, modify or populate fields of data records).
Waplington does not explicitly state wherein the application is a cyber-security analysis tool utilizing the data entries and that the data entries are related to cyber security events. However, managing cyber security records in such a fashion was well known in the art as evidenced by Lambert. Since the inventions encompass the same field of endeavor, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the system of Waplington by adding the ability that the application is a cyber-security analysis tool utilizing the data entries and that the data entries are related to cyber security events as provided by Lambert (see paragraph 17, programmatic and human analysis of security data). One of ordinary skill in the art would have recognized the benefit that managing cyber security records in this way would assist in increasing efficiency and prioritization when addressing resource security incidents (see Lambert, paragraph 3).
Regarding claim 3, the combination of Waplington and Lambert discloses wherein the instructions further cause the computer system to: edit a data entry within the database; and update the history record of the data entry (Waplington, paragraph 76, entry updated and update added to history for the entry).
Regarding claim 4, the combination of Waplington and Lambert discloses wherein the plurality of data sources further includes an internal computing system, the internal computing system being part of an internal network including the computer system (Waplington, paragraph 57, source is application instance of same cloud service).
Regarding claim 5, the combination of Waplington and Lambert discloses wherein refining includes processing the data with business logic (Waplington, paragraph 91, inbound processing logic).
Regarding claim 6, the combination of Waplington and Lambert discloses wherein the instructions further cause the computer system to: responsive to a reception of the data entries, perform controls to ingest the data entries (Waplington, paragraph 61, inbound data record processing).
Regarding claim 7, the combination of Waplington and Lambert discloses wherein the controls include a data receipt control (Waplington, paragraph 63, received data record stored).
Regarding claim 8, the combination of Waplington and Lambert discloses wherein the controls include a data completeness management control (Waplington, paragraph 63, correlation index updated).
Regarding claim 9, the combination of Waplington and Lambert discloses wherein the instructions further cause the computer system to: determine a source for the data entries; and select a control to ingest the data entries based on a determined source (Waplington, paragraph 38, requested source instance, and paragraph 57, received data processed with correlation configuration).
Regarding claim 10, the combination of Waplington and Lambert discloses wherein the instructions further cause the computer system to: perform a selected control (Waplington, paragraph 38, correlation controlled by correlation configuration).
Regarding claim 11, Waplington discloses a method for ingesting data from multiple sources, the method comprising: receiving, from a plurality of data sources, data entries, the plurality of data sources including an external computing device and an application programming interface (paragraph 19, data records correlated across different instances with sources on different application servers on different network domains); determining an application for use of the data entries (paragraph 58, matches update event for target instance); transforming the data entries for storage in a database (paragraph 61, modify received data records to create version for target instance); curating a history record of the data entries stored in the database (paragraph 34, correlation history), wherein the history record includes prior versions of the data entries that are rendered inactive upon storage of updated versions of the data entries (paragraph 67, each correlation entry includes history of changes); and refining the data entries for use with the application (paragraph 61, modify or populate fields of data records).
Waplington does not explicitly state wherein the application is a cyber-security analysis tool utilizing the data entries and that the data entries are related to cyber security events. However, managing cyber security records in such a fashion was well known in the art as evidenced by Lambert. Since the inventions encompass the same field of endeavor, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the system of Waplington by adding the ability that the application is a cyber-security analysis tool utilizing the data entries and that the data entries are related to cyber security events as provided by Lambert (see paragraph 17, programmatic and human analysis of security data). One of ordinary skill in the art would have recognized the benefit that managing cyber security records in this way would assist in increasing efficiency and prioritization when addressing resource security incidents (see Lambert, paragraph 3).
Regarding claim 13, the combination of Waplington and Lambert discloses editing a data entry within the database; and updating the history record of the data entry (Waplington, paragraph 76, entry updated and update added to history for the entry).
Regarding claim 14, the combination of Waplington and Lambert discloses wherein the plurality of data sources further includes an internal computing system, the internal computing system being part of an internal network (Waplington, paragraph 57, source is application instance of same cloud service).
Regarding claim 15, the combination of Waplington and Lambert discloses wherein refining includes processing the data entries with business logic (Waplington, paragraph 91, inbound processing logic).
Regarding claim 16, the combination of Waplington and Lambert discloses responsive to a reception of the data entries, performing controls to ingest the data entries (Waplington, paragraph 61, inbound data record processing).
Regarding claim 17, the combination of Waplington and Lambert discloses wherein the controls include a data receipt control (Waplington, paragraph 63, received data record stored).
Regarding claim 18, the combination of Waplington and Lambert discloses wherein the controls include a data completeness management control (Waplington, paragraph 63, correlation index updated).
Regarding claim 19, the combination of Waplington and Lambert discloses determining a source for the data entries; and selecting a control to ingest the data entries based on determining the source (Waplington, paragraph 38, requested source instance, and paragraph 57, received data processed with correlation configuration).
Regarding claim 20, the combination of Waplington and Lambert discloses performing a selected control (Waplington, paragraph 38, correlation controlled by correlation configuration).
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to Victor Lesniewski whose telephone number is (571)272-2812. The examiner can normally be reached Monday thru Friday, 9am to 5pm.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached at 571-272-3862. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/Victor Lesniewski/Primary Examiner, Art Unit 2493